Zero-Click Vulnerability Exposes Major AI Coding Agents to Remote Code Execution
September 17, 2026
oecd:2026-09-17-b58dView source ↗
What happened
A critical zero-click vulnerability, Plugin4Shell, was discovered in major AI coding agents—Claude Code, Codex, GitHub Copilot, and Gemini CLI—allowing attackers to execute malicious code by exploiting plugin verification flaws. While Anthropic and OpenAI patched their agents, GitHub Copilot remains unpatched, exposing enterprise systems to significant risk.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
OECD AI Incidents Monitor
Zero-Click Vulnerability Exposes Major AI Coding Agents to Remote Code Execution
2026-09-17