{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0444",
  "aliases": [],
  "published": "2026-09-18T00:00:00Z",
  "modified": "2026-09-25T00:00:00Z",
  "summary": "Changed plugin code could be installed under a reviewed, pinned marketplace plugin revision and run with the user's privileges in Claude Code, Codex, GitHub Copilot and Gemini CLI.",
  "details": "## What\n\nAIR's Plugin4Shell disclosure described a supply-chain defect shared by four coding agents: plugin pinning did not reliably ensure that the installed code matched the reviewed revision. A malicious plugin could then run with the same access as the agent, including access to files, credentials and connected systems.\n\n## Detection\n\nAIR demonstrated proof-of-concept exploits against all four agents; the report is not a lab recreation by this registry.\n\n## Fix\n\nUpgrade Claude Code to 2.1.179 and Codex to 0.146.0; GitHub Copilot remained unpatched in the report, and Google said Gemini CLI would not be fixed because it was being retired.",
  "affected": [
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "claude-code"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2.1.179"
            }
          ]
        }
      ]
    },
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "codex-cli"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.146.0"
            }
          ]
        }
      ]
    },
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "github-copilot"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    },
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "gemini-cli"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    }
  ],
  "references": [
    {
      "type": "REPORT",
      "url": "https://www.helpnetsecurity.com/2026/09/18/plugin4shell-ai-coding-agents-vulnerability/"
    },
    {
      "type": "REPORT",
      "url": "https://aviatrix.ai/threat-research-center/plugin4shell-ai-coding-agents-supply-chain-2026/"
    }
  ],
  "database_specific": {
    "severity": "CRITICAL",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "code",
      "vulnClasses": [
        "supply-chain",
        "rug-pull",
        "tool-poisoning",
        "credential-exposure"
      ],
      "cwe": [
        "CWE-494",
        "CWE-693"
      ],
      "taxonomy": {
        "owasp_asi": [
          "ASI04"
        ],
        "atlas": [
          "AML.T0109",
          "AML.T0010.005"
        ]
      },
      "cveBoundary": "supply-chain",
      "noCveReason": "No CVE was assigned in the public disclosure.",
      "exploitation": {
        "status": "weaponised-poc",
        "checkedAt": "2026-09-24T00:00:00Z",
        "sources": [
          {
            "url": "https://www.helpnetsecurity.com/2026/09/18/plugin4shell-ai-coding-agents-vulnerability/",
            "type": "research"
          }
        ],
        "kev": {
          "listed": false
        }
      },
      "fix": {
        "summary": "Upgrade patched agents and remove plugins from unpatched agents until their pinning is fixed.",
        "actions": [
          {
            "type": "upgrade",
            "target": "harness:claude-code",
            "to": "2.1.179",
            "why": "Version stated by the report.",
            "owner": "operator"
          },
          {
            "type": "upgrade",
            "target": "harness:codex-cli",
            "to": "0.146.0",
            "why": "Version stated by the report.",
            "owner": "operator"
          }
        ]
      },
      "exposure": {
        "harness": {
          "value": "Claude Code, Codex, GitHub Copilot or Gemini CLI with a marketplace plugin installed",
          "any": false,
          "status": "confirmed",
          "source": "https://www.helpnetsecurity.com/2026/09/18/plugin4shell-ai-coding-agents-vulnerability/"
        },
        "model": {
          "value": "any",
          "any": true,
          "status": "unconfirmed"
        },
        "goal": {
          "value": "Any coding task that loads an installed plugin",
          "stated": false,
          "status": "unconfirmed"
        },
        "tools": {
          "value": "Marketplace plugins and the agent's revision-pinning check",
          "status": "confirmed",
          "source": "https://aviatrix.ai/threat-research-center/plugin4shell-ai-coding-agents-supply-chain-2026/"
        },
        "approval": {
          "value": "The plugin is trusted and loaded after review and pinning, but the installed code may differ from the reviewed revision",
          "mode": "none-required",
          "status": "detected",
          "source": "https://www.helpnetsecurity.com/2026/09/18/plugin4shell-ai-coding-agents-vulnerability/"
        },
        "inputControl": "package-publisher",
        "agentAction": "The agent installs and runs plugin code that is not the reviewed pinned revision.",
        "harm": "arbitrary-command",
        "divergence": "none",
        "reach": {
          "value": "Files, credentials and connected systems available to the agent",
          "kinds": [
            "project-files",
            "cloud-credentials",
            "network"
          ],
          "status": "confirmed",
          "source": "https://aviatrix.ai/threat-research-center/plugin4shell-ai-coding-agents-supply-chain-2026/"
        }
      },
      "reproducibility": {
        "status": "partial",
        "axesComplete": true,
        "componentsObtainable": null,
        "triggerPublished": false,
        "observableStated": true,
        "demonstrated": "researcher-demonstrated",
        "missing": [
          "vulnerable components are not confirmed obtainable",
          "trigger not published"
        ]
      }
    }
  }
}
