Zero-Click Vulnerability Exposes Major AI Coding Agents to Remote Code Execution

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

A critical zero-click vulnerability, Plugin4Shell, was discovered in major AI coding agents—Claude Code, Codex, GitHub Copilot, and Gemini CLI—allowing attackers to execute malicious code by exploiting plugin verification flaws. While Anthropic and OpenAI patched their agents, GitHub Copilot remains unpatched, exposing enterprise systems to significant risk.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves AI systems explicitly (AI coding agents) and describes a security vulnerability (malfunction) that directly leads to harm by enabling remote code execution and unauthorized access to data and assets. This constitutes harm to property and potentially to communities relying on these AI systems. The exploit affects multiple major AI systems and has been demonstrated at scale, confirming realized harm potential. Therefore, this qualifies as an AI Incident due to the direct link between the AI system's malfunction and significant harm.[AI generated]
AI principles
Robustness & digital securityAccountability

Industries
Digital security

Affected stakeholders
Business

Harm types
Economic/PropertyReputational

Business function:
Research and development

AI system task:
Content generation


Articles about this incident or hazard