TGViewer
Linux Linux @sysadminoff · 2.14K subscribers
Post #20202 59
Plugin4Shell leaves Copilot and Gemini CLI exposed to zero-click RCE

GitHub Copilot and deprecated Gemini CLI remain exposed to Plugin4Shell, a zero-click remote-code-execution flaw affecting four major AI coding agents. Anthropic and OpenAI have released fixes for Claude Code and Codex, but organizations using the other two agents must migrate or apply compensating controls because marketplace protections cannot block the attack.
Source

👉@sysadminoff

https://4sysops.com/archives/plugin4shell-leaves-copilot-and-gemini-cli-exposed-to-zero-click-rce/
More from @sysadminoff
  1. Sep 29, 2026Метод атаки, значительно сокращающий ресурсы для подделки цифровых подписей RSA Исследоват…
  2. Sep 29, 2026📰 Wisp Makes It Easier To Manage Btrfs Snapshots From The GNOME Desktop Wisp is a new GNO…
  3. Sep 29, 2026📰 I built one folder that automatically stays in sync across every computer I own without…
  4. Sep 29, 2026📰 AMDXDNA Linux Driver Being Enhanced For Current NPU3 Hardware The AMDXDNA open-source L…
  5. Sep 29, 2026Grok 4.7 arrives on Amazon Bedrock with a 500K-token context window xAI’s Grok 4.7 is now…
  6. Sep 29, 2026Word may hide network-drive PDFs in Windows cache with random names Microsoft has confirme…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →