/Submit incident
Documented

Zero-Click Vulnerability Exposes Major AI Coding Agents to Remote Code Execution

September 17, 2026
oecd:2026-09-17-b58dView source ↗

What happened

A critical zero-click vulnerability, Plugin4Shell, was discovered in major AI coding agents—Claude Code, Codex, GitHub Copilot, and Gemini CLI—allowing attackers to execute malicious code by exploiting plugin verification flaws. While Anthropic and OpenAI patched their agents, GitHub Copilot remains unpatched, exposing enterprise systems to significant risk.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

OECD AI Incidents Monitor
Primary source
Zero-Click Vulnerability Exposes Major AI Coding Agents to Remote Code Execution
2026-09-17