- Sources: primary
- Summary: The Register describes a flaw the research firm Air calls Plugin4Shell as a plugin SHA-pinning bypass, in which the agent checks out the exact commit the marketplace pinned but never verifies the content that landed there, so an attacker controlling the plugin repository makes the checkout resolve to malicious code while the pin still reads as honored, reaching code execution with no user action. Claude Code 2.1.179 and Codex 0.146.0 are named as the fixed versions while Gemini CLI and Microsoft Copilot shipped no patch, and plugin auto-update widens the reach, because control of a marketplace then becomes silent code execution on every machine that installs from it. Air's own report was not reachable on this run, so the account here is The Register's, which carries GitHub's statement that the attacks do not affect GitHub because it blocks branch and tag names resembling commit SHAs, Air's rebuttal that the mitigation is insufficient because marketplaces can be hosted on Bitbucket and Copilot supports those, a second-hand relay that Google told Air it will not patch Gemini CLI, and no answer from Microsoft, with no CVE apparently assigned.
- Why it matters: Claude Code and Codex shipped fixes while Copilot and the deprecated Gemini CLI did not, which leaves Copilot's Fortune 500 install base without a vendor fix and leaves Gemini CLI users with migration to Google's Antigravity environment as the stated path.
- Follow-up: Track Air's own disclosure, a CVE assignment, and whether Microsoft patches Copilot.
send feedback on this story