Security researchers disclosed “Plugin4Shell,” a zero-click remote code execution vulnerability affecting Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI. The flaw breaks SHA pinning, the mechanism meant to lock an installed plugin to a reviewed version, letting an attacker swap in malicious code after a plugin passes review or by hijacking a legitimate plugin author’s repository. Because these agent plugins typically inherit the same permissions as the developer running them, exploitation could expose source code, cloud credentials, SSH keys, and production systems without any user action. Anthropic and OpenAI patched their products, Google opted to deprecate Gemini CLI rather than fix it, and GitHub had not released a fix for Copilot as of the disclosure.