Plugin4Shell leaves Copilot and Gemini CLI exposed to zero-click RCE
GitHub Copilot and deprecated Gemini CLI remain exposed to Plugin4Shell, a zero-click remote-code-execution flaw affecting four major AI coding agents. Anthropic and OpenAI have released fixes for Claude Code and Codex, but organizations using the other two agents must migrate or apply compensating controls because marketplace protections cannot block the attack.
Source
👉@sysadminoff
https://4sysops.com/archives/plugin4shell-leaves-copilot-and-gemini-cli-exposed-to-zero-click-rce/
Post #20202
59
