Plugin4Shell: Four AI Coding Agents Pinned Plugins to a Hash They Never Checked
- ID: a72a196d
- 原文链接: https://recatools.com/news/plugin4shell-sha-pinning-bypass-ai-coding-agents-2026/
- 作者: AIR Security
- 日期: 2026-09-19
- 分类: auto
- 来源类型: article
- 标签: ai-coding-agent, supply-chain, plugin-pinning, security, claude-code, codex, gemini-cli, copilot
- 质量评分: 5/5
- 抓取时间: 2026-09-20T23:30Z
中文摘要
AIR Security 09-17 披露 Plugin4Shell:四个 AI coding agent(Claude Code / Codex / Gemini CLI / GitHub Copilot)装插件时记录 40 位 commit hash 让 git checkout 该 commit,但从不验证 working tree 是否真的等于这个 hash。git 的歧义名解析规则是分支名先于 commit hash——仓库里建一个与 40 位 hash 同名的 branch 指向任意代码,agent 检出它还报告"已安装 pinned 版本"。Anthropic 在 Claude Code 2.1.179 修复(06-17 确认),OpenAI 在 Codex 0.146.0 修复(08-12 确认),用户 09-17 才被告知;Google 08-04 拒绝修(即将退役 Gemini CLI);GitHub Copilot 至今无修复、无修复时间表、无 CVE。风险集中在自建/第三方 git 托管的插件源——GitHub 本身禁止分支名长得像 commit hash。
为什么值得关注
Claude Code / Codex 已修,Copilot 没修也没时间表——pin 而不验收是整个自动化生态的通病,AI agent 只是最近一例。
English Abstract
AIR Security disclosed Plugin4Shell on 2026-09-17: four AI coding agents (Claude Code, Codex, Gemini CLI, GitHub Copilot) record a 40-character commit hash and git checkout that hash when installing plugins, but never verify that the resulting working tree actually matches the requested hash. Git's ambiguous-name resolution prefers branch names over commit hashes, so an attacker who controls the plugin repo can create a branch named identically to the 40-char hash pointing at arbitrary code; the agent checks it out and reports the pinned version as installed. Anthropic fixed it in Claude Code 2.1.179 (confirmed 06-17), OpenAI in Codex 0.146.0 (08-12); users were not informed until 09-17. Google refused to patch on 08-04 (Gemini CLI being retired). GitHub Copilot still has no fix, no timeline, and no CVE. Risk concentrates on self-hosted / third-party git plugin registries since GitHub itself blocks branch names resembling commit hashes.
Obsidian 证据摘要
来源: OpenClaw定时任务/DevRadar/2026-09-20-DevRadar.md (P1)
原文摘录
# Four AI Coding Agents Pinned Plugins to a Hash They Never Checked
> 原文链接: https://recatools.com/news/plugin4shell-sha-pinning-bypass-ai-coding-agents-2026/
---
AI & ML · 19 Sep 2026 —
Advertisement
**19 SEP 2026** — Four AI coding agents pinned their plugins to an exact commit hash, then never checked that the code they got back matched it.
Anthropic and OpenAI fixed the problem in June and August. Users were told on 17 September. GitHub Copilot has no fix, and Google will not write one.
## How the pin fails
An agent installing a plugin does what a careful engineer would: it records a 40-character commit hash and asks git for exactly that commit. The intent is that the reviewed code is the code that runs.
The agents failed to account for a git rule about ambiguous names. If a repository contains a branch whose name is identical to that 40-character hash, git resolves the branch first. Someone who controls the plugin repository can create such a branch, point it at whatever they like, and the agent checks it out while reporting that it installed the pinned version.
[AIR Security](https://www.air.security/blog-posts/plugin4shell), which found the flaw and named it Plugin4Shell, describes the missing step precisely: the agents never verify that the resulting working tree matches the hash they asked for. Gemini CLI fails a variant of the same check, resolving a branch named FETCH\_HEAD ahead of the commit it had just fetched.
## What each vendor did
Anthropic shipped a fix in Claude Code 2.1.179 and confirmed it on 17 June. OpenAI's fix was verified in Codex 0.146.0 on 12 August. Both landed months before anyone outside the vendors knew there was a problem.
Google told the researchers on 4 August that it would not patch Gemini CLI, which it is retiring, and pointed users to its replacement. GitHub Copilot has no fix at all.
No CVE identifiers had been assigned when [The Hacker News reported the disclosure](https://thehackernews.com/2026/09/plugin4shell-lets-repository-owners.html) on 18 September. The flaw carries no tracking number for anyone building a patch inventory.
**4**Agents affected
**2**With a fix
**17 Jun**First vendor fix confirmed
**17 Sep**When users were told
## Where the real exposure sits
GitHub does not permit branch or tag names that look like commit hashes, so a plugin hosted there cannot be attacked this way. That detail narrows the exposure considerably.
The exposure is concentrated in plugins hosted outside GitHub, on infrastructure the attacker controls or can compromise. That is a smaller population than the four agent names suggest. AIR Security's count of millions of affected agents describes installed agents, not exploitable plugin sources.
No exploitation has been observed. The researchers built working attacks in May and found no evidence that anyone else had.
## Three months between fix and notice
The timeline is where the argument sits. AIR Security disclosed to all four vendors in June, and two fixed quickly. The public learned in September. By then, users of the patched agents had been safe for months without knowing why; users of the unpatched two had been exposed for months without knowing at all.
Coordinated disclosure exists to give vendors time to ship before attackers learn the technique, and on that measure it worked. It also means a Copilot user had no way to make an informed decision through July and August. That is the trade-off.
Advertisement
## What is still unresolved
Copilot is the one to watch. It is the most widely deployed of the four and the only one that is neither patched nor retired, with no fix date given.
The second unresolved question is whether the pattern extends beyond plugins. The failure is not specific to AI agents. Any automated system that trusts a version pin without verifying what it received has the same problem; plugin installation is just where someone looked.
A CVE would help. Without one, the flaw is hard to track through the tools organisations use to decide what to patch, and a vulnerability nobody can reference is easy to ignore.
Advertisement
Tags: [#AI-Agents](https://recatools.com/tag/ai-agents/) [#Supply-Chain-Security](https://recatools.com/tag/supply-chain-security/) [#Vulnerabilities](https://recatools.com/tag/vulnerabilities/)
[Kenji Tanaka](https://recatools.com/authors/kenji-tanaka)
Developer Tools & Cloud Analyst
Kenji Tanaka covers developer tools, cloud platforms, DevOps, CI/CD, and software supply-chain topics for RECATOOLS.
[View author profile →](https://recatools.com/authors/kenji-tanaka) · [Editorial policy](https://recatools.com/editorial-policy)
**About this byline** Kenji Tanaka is a RECATOOLS editorial persona for developer tools, cloud, DevOps, and software supply-chain coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.
[Corrections policy](https://recatools.com/corrections-policy) · Spotted an error?