{"id":3597,"date":"2026-09-21T12:33:55","date_gmt":"2026-09-21T12:33:55","guid":{"rendered":"https:\/\/netguide.io\/news\/2026\/09\/21\/plugin4shell-vulnerability-threatens-ai-assistants-from-openai-google-and-anthropic\/"},"modified":"2026-09-21T12:33:56","modified_gmt":"2026-09-21T12:33:56","slug":"plugin4shell-vulnerability-threatens-ai-assistants-from-openai-google-and-anthropic","status":"publish","type":"post","link":"https:\/\/netguide.io\/news\/en\/2026\/09\/21\/plugin4shell-vulnerability-threatens-ai-assistants-from-openai-google-and-anthropic\/","title":{"rendered":"Plugin4Shell: Vulnerability Threatens AI Assistants from OpenAI, Google, and Anthropic"},"content":{"rendered":"<div id=\"netgu-1793609111\" class=\"netgu-before-content netgu-entity-placement\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-6258556257245998\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-6258556257245998\" \ndata-ad-slot=\"3494115342\" \ndata-ad-format=\"auto\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>A critical vulnerability dubbed Plugin4Shell is jeopardizing the systems of software developers using AI-based programming assistants. Through manipulated extensions on marketplaces, attackers can achieve remote code execution (RCE) without any user interaction. Affected tools include Anthropic&#8217;s Claude Code, OpenAI Codex, GitHub Copilot, and Google&#8217;s Gemini CLI.<\/p>\n<h2>Forged Git Branches Bypass Integrity Checks<\/h2>\n<p>The flaw was discovered by IT security firm AIR Security back in May 2026. The issue lies in the way coding agents retrieve external extensions. By design, the tools request a 40-character SHA fingerprint from marketplaces\u2014a cryptographic checksum intended to ensure that exactly the pre-verified version of a software package (commit) is installed.<\/p><div id=\"netgu-1859744687\" class=\"netgu-content netgu-entity-placement\"><aside class=\"deals-top deals-top--compact\">\n\n\t\t\t<h3 class=\"deals-top__title\">Top-Deals<\/h3>\n\t\n\t\t\t<ul class=\"deals-top__list\">\n\t\t\t\t\t\t\t<li class=\"deals-top__item\">\n\t\t\t\t\t<a class=\"deals-top__link\" href=\"https:\/\/netguide.io\/deals\/de\/deals\/ugreen-aluminium-tabletstaender-360-drehbar-hoehenverstellbar\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<img class=\"deals-top__image\" src=\"https:\/\/netguide.io\/news\/wp-content\/uploads\/sites\/15\/2026\/09\/2825012_1-150x150.webp\" alt=\"\" width=\"52\" height=\"52\" loading=\"lazy\" \/>\n\t\t\t\t\t\t\n\t\t\t\t\t\t<span class=\"deals-top__body\">\n\t\t\t\t\t\t\t<span class=\"deals-top__name\">UGREEN Aluminium Tabletst\u00e4nder | 360\u00b0 Drehbar &amp; H\u00f6henverstellbar<\/span>\n\n\t\t\t\t\t\t\t<span class=\"deals-top__meta\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"deals-top__price\">16.91 \u20ac<\/span>\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<s>20.37 \u20ac<\/s>\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"deals-discount\">-17%<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\n\t\t\t\t\t\t<span class=\"deals-top__temperature is-hot\">\n\t\t\t\t\t\t\t109\u00b0\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t<li class=\"deals-top__item\">\n\t\t\t\t\t<a class=\"deals-top__link\" href=\"https:\/\/netguide.io\/deals\/de\/deals\/train-sim-world-7-starter-pack-kostenlos-fuer-ps4-ps5-xbox-pc\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<img class=\"deals-top__image\" src=\"https:\/\/netguide.io\/news\/wp-content\/uploads\/sites\/15\/2026\/09\/capsule_616x353-11-150x150.jpg\" alt=\"\" width=\"52\" height=\"52\" loading=\"lazy\" \/>\n\t\t\t\t\t\t\n\t\t\t\t\t\t<span class=\"deals-top__body\">\n\t\t\t\t\t\t\t<span class=\"deals-top__name\">Train Sim World 7: Starter Pack kostenlos f\u00fcr PS4, PS5, Xbox, PC<\/span>\n\n\t\t\t\t\t\t\t<span class=\"deals-top__meta\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"deals-top__price\">Gratis<\/span>\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\n\t\t\t\t\t\t<span class=\"deals-top__temperature\">\n\t\t\t\t\t\t\t55\u00b0\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t<li class=\"deals-top__item\">\n\t\t\t\t\t<a class=\"deals-top__link\" href=\"https:\/\/netguide.io\/deals\/de\/deals\/kostenlose-emote-im-clash-royale-store\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<img class=\"deals-top__image\" src=\"https:\/\/netguide.io\/news\/wp-content\/uploads\/sites\/15\/2026\/09\/share-image-clashroyale-150x150.jpg\" alt=\"\" width=\"52\" height=\"52\" loading=\"lazy\" \/>\n\t\t\t\t\t\t\n\t\t\t\t\t\t<span class=\"deals-top__body\">\n\t\t\t\t\t\t\t<span class=\"deals-top__name\">Kostenlose Emote im Clash Royale-Store<\/span>\n\n\t\t\t\t\t\t\t<span class=\"deals-top__meta\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"deals-top__price\">Gratis<\/span>\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\n\t\t\t\t\t\t<span class=\"deals-top__temperature\">\n\t\t\t\t\t\t\t54\u00b0\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t<li class=\"deals-top__item\">\n\t\t\t\t\t<a class=\"deals-top__link\" href=\"https:\/\/netguide.io\/deals\/de\/deals\/gratis-forschungssuppe-im-clash-of-clans-store\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<img class=\"deals-top__image\" src=\"https:\/\/netguide.io\/news\/wp-content\/uploads\/sites\/15\/2026\/09\/2839474_1-150x150.webp\" alt=\"\" width=\"52\" height=\"52\" loading=\"lazy\" \/>\n\t\t\t\t\t\t\n\t\t\t\t\t\t<span class=\"deals-top__body\">\n\t\t\t\t\t\t\t<span class=\"deals-top__name\">Gratis Forschungssuppe im Clash of Clans-Store<\/span>\n\n\t\t\t\t\t\t\t<span class=\"deals-top__meta\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"deals-top__price\">Gratis<\/span>\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\n\t\t\t\t\t\t<span class=\"deals-top__temperature\">\n\t\t\t\t\t\t\t54\u00b0\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t<li class=\"deals-top__item\">\n\t\t\t\t\t<a class=\"deals-top__link\" href=\"https:\/\/netguide.io\/deals\/de\/deals\/the-clockwork-scarab-stoker-and-holmes-book-1-kindle-edition\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<img class=\"deals-top__image\" src=\"https:\/\/netguide.io\/news\/wp-content\/uploads\/sites\/15\/2026\/09\/4982769_1-150x150.webp\" alt=\"\" width=\"52\" height=\"52\" loading=\"lazy\" \/>\n\t\t\t\t\t\t\n\t\t\t\t\t\t<span class=\"deals-top__body\">\n\t\t\t\t\t\t\t<span class=\"deals-top__name\">The Clockwork Scarab (Stoker and Holmes Book 1) \u2013 Kindle Edition<\/span>\n\n\t\t\t\t\t\t\t<span class=\"deals-top__meta\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"deals-top__price\">Gratis<\/span>\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<s>0.01 \u20ac<\/s>\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"deals-discount\">-100%<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\n\t\t\t\t\t\t<span class=\"deals-top__temperature\">\n\t\t\t\t\t\t\t54\u00b0\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t<\/ul>\n\n\t\t\t\t\t<p class=\"deals-top__more\">\n\t\t\t\t<a href=\"https:\/\/netguide.io\/deals\/\">Alle Deals ansehen \u2192<\/a>\n\t\t\t<\/p>\n\t\t\t<\/aside>\n<\/div>\n<p>In practice, however, the affected tools did not verify whether the code&#8217;s actual hash matched this fingerprint after downloading. Attackers with access to a plugin vendor&#8217;s repository could thus create a development branch whose name exactly mirrors the expected hash and populate it with malicious code. If this manipulated branch is made the default, the AI agent downloads and directly executes the malicious code instead of the verified version during the next automatic update.<\/p>\n<p>According to the researchers, this technique works on marketplaces hosted on Bitbucket, GitLab, or self-hosted Git servers. GitHub itself blocks the creation of branch names formatted like Git hashes. There are no known instances of this vulnerability being exploited in the wild so far.<\/p>\n<h2>Patch Status: Anthropic and OpenAI Deliver, Copilot Remains Open<\/h2>\n<p>The vendors were notified of the attack vector in June 2026, though their responses have varied significantly. Anthropic resolved the vulnerability with version 2.1.179 of Claude Code. OpenAI also rolled out a fix, which has been integrated into Codex version 0.146.0 since early August.<\/p>\n<p>Users of Microsoft&#8217;s GitHub Copilot, on the other hand, will have to wait longer: no patch is currently available for the tool, and the vendor has not responded to the discoverers. The vulnerability joins a series of incidents where interfaces of modern large language models pose a risk\u2014only recently, a <a href=\"https:\/\/netguide.io\/news\/de\/2026\/09\/20\/sicherheitspanne-google-ki-gemini-bricht-aus-testumgebung-in-produktivsysteme-aus\/\" rel=\"nofollow noopener\">security incident in which Google&#8217;s Gemini escaped test environments<\/a> demonstrated how delicate these agent execution environments are.<\/p>\n<h2>Gemini CLI Discontinued<\/h2>\n<p>For users of the consumer version of Google&#8217;s Gemini CLI, there is bad news: the tool will remain permanently vulnerable. Google confirmed to the security researchers that the consumer edition of the command-line tool is being discontinued and will not receive any further security updates. Enterprise access via Gemini Code Assist or Google Cloud remains unaffected by this deprecation.<\/p>\n<p>Developers using Claude Code or OpenAI Codex should immediately verify that their installations are up to date. Users of the consumer version of Gemini CLI should uninstall the application and switch to alternatives such as Antigravity CLI, which does not employ a comparable SHA pinning mechanism for marketplace plugins. For GitHub Copilot, caution is advised when integrating third-party extensions until a corresponding update is released.<\/p>\n<p><em>Sources: <a href=\"https:\/\/www.heise.de\/news\/Kritische-Luecke-bei-Claude-Code-OpenAI-Codex-GitHub-Copilot-und-Gemini-CLI-11459862.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag\" rel=\"nofollow noopener\" target=\"_blank\">Heise &#8211; News<\/a><\/em><\/p>\n<div id=\"netgu-1013450158\" class=\"netgu-after-content netgu-entity-placement\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-6258556257245998\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-6258556257245998\" \ndata-ad-slot=\"4559785002\" \ndata-ad-format=\"auto\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A critical zero-click vulnerability enables remote code execution via AI developer tools. While OpenAI and Anthropic have issued updates, Google&#8217;s Gemini CLI remains unpatched.<\/p>\n","protected":false},"author":1,"featured_media":3346,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[430],"tags":[2106,1328,2963,1441,2118,2964],"class_list":["post-3597","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-en","tag-anthropic-en","tag-cybersecurity-en","tag-github-en","tag-google-en","tag-openai-en","tag-software-development"],"brizy_media":[],"_links":{"self":[{"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/posts\/3597","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/comments?post=3597"}],"version-history":[{"count":1,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/posts\/3597\/revisions"}],"predecessor-version":[{"id":3598,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/posts\/3597\/revisions\/3598"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/media\/3346"}],"wp:attachment":[{"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/media?parent=3597"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/categories?post=3597"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/tags?post=3597"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}