Tuesday, 22 September 2026

Search
Latent Digest

TECHNOLOGY, TRACKED ACROSS DISCIPLINES

Compute & Hardware

Zero-click RCE found in four AI coding agents, two unpatched

Researchers say a single zero-click flaw in Claude Code, Codex, GitHub Copilot, and Gemini CLI could let attackers act with the same privileges as the employee using the agent.

· 1 min read · 2 sources

Both Help Net Security and The Register report that four major AI coding agents share a zero-click remote code execution vulnerability. The flaw, called Plugin4Shell, is present in Claude Code, Codex, GitHub Copilot, and Gemini CLI, according to both publications.

The risk is severe because no user interaction is required. Help Net Security attributes the finding to researchers at AIR and warns that an attacker can gain the same reach into a company's systems and data as the employee running the agent. The Register similarly frames the flaw as one that could hand attackers the keys to the kingdom.

The two reports differ on remediation status. Help Net Security's headline states that two of the four agents remain unpatched, though the excerpt does not name them. The Register's coverage does not mention patch status in the available excerpt, so readers should consult vendor advisories for current fixes.

Sources · 2

  1. 01Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatchedHelp Net Security
  2. 02AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdomThe Register

More in Compute & Hardware