Zero-click RCE found in four AI coding agents, two unpatched
Researchers say a single zero-click flaw in Claude Code, Codex, GitHub Copilot, and Gemini CLI could let attackers act with the same privileges as the employee using the agent.
Both Help Net Security and The Register report that four major AI coding agents share a zero-click remote code execution vulnerability. The flaw, called Plugin4Shell, is present in Claude Code, Codex, GitHub Copilot, and Gemini CLI, according to both publications.
The risk is severe because no user interaction is required. Help Net Security attributes the finding to researchers at AIR and warns that an attacker can gain the same reach into a company's systems and data as the employee running the agent. The Register similarly frames the flaw as one that could hand attackers the keys to the kingdom.
The two reports differ on remediation status. Help Net Security's headline states that two of the four agents remain unpatched, though the excerpt does not name them. The Register's coverage does not mention patch status in the available excerpt, so readers should consult vendor advisories for current fixes.
Sources · 2
More in Compute & Hardware
Accelerated Server Sales Show Accelerating Growth
A report from The Next Platform finds that sales of accelerated servers are growing at an increasing pace.
FCT Unveils Flex Circuit Leak Sensor for AI and HPC Liquid Cooling
Flexible Circuit Technologies has developed a custom leak-detection flex assembly aimed at protecting AI and high-performance computing systems from coolant failures.
Hardware Trojan Detection: Stable Patterns Found in Gate-Level Netlists
A new study from UW-Madison and Marist shows that RTL Trojans leave stable structural and signal-flow traces that can be localized at the gate level.
DKRZ Joins EU Project for AI Climate Models on HPC
Germany's climate computing centre is part of a new four-year Horizon Europe effort to make AI-based climate models usable on European supercomputing and AI infrastructure.