Technology ← Home

On September 18, 2026 The Hacker News reported Air Security's Plugin4Shell SHA-pinning bypass on Claude Code, Codex, GitHub Copilot, and Gemini CLI, that Anthropic patched Claude Code 2.1.179 and OpenAI patched Codex 0.146.0 while Copilot had no fix per Air and Google will not patch deprecated Gemini CLI and points users to Antigravity, that GitHub rejects 40-hex branch names so default marketplace plugins are not exposed to that trick while Bitbucket and self-hosted setups can allow it, that Gemini CLI has a separate FETCH_HEAD path, that Claude Code and Codex default to background auto-update creating a zero-click path, that the issue was found in May 2026 and disclosed in June with no CVE and no known real-world attack as of September 18, and that Help Net Security framed it as the first AI-agent supply-chain vulnerability citing SkillJacking prior art and a fake-plugin test that reached more than 26,000 agents; unfinished patch rollout plus unfinished Copilot and Gemini CLI exposure is not already AI coding agents safe forever and not already every install owned forever

NewsCorrections Staff · Friday, September 18, 2026 · 6 min read
Corrected from Thehackernews: “Unfinished patch rollout and unfinished Copilot and Gemini CLI exposure are not already AI coding agents safe forever and not already every install owned forever”

On September 18, 2026 The Hacker News reported that Air Security documented Plugin4Shell, a SHA-pinning bypass affecting Claude Code, Codex, GitHub Copilot, and Gemini CLI. Anthropic patched Claude Code in 2.1.179 and OpenAI patched Codex in 0.146.0. Copilot had no fix per Air. Google will not patch the deprecated Gemini CLI and points users to migrate to Antigravity. GitHub rejects 40-hex branch names, limiting default marketplace exposure, while Bitbucket and self-hosted setups can allow the branch-name trick. Gemini CLI uses a separate FETCH_HEAD mechanism. Background auto-update defaults in Claude Code and Codex create a zero-click path. The issue was found in May 2026 and disclosed in June; as of September 18 there was no CVE and no known real-world attack. Help Net Security framed Plugin4Shell as the first supply-chain vulnerability of the AI agent ecosystem, citing SkillJacking prior art and a fake-plugin test that reached more than 26,000 agents. Unfinished patch rollout plus unfinished Copilot and Gemini CLI exposure are real. They are not already AI coding agents safe forever, and they are not already every install owned forever.

On September 18, 2026 The Hacker News reported Air Security's Plugin4Shell SHA-pinning bypass on Claude Code, Codex, GitHub Copilot, and Gemini CLI, that Anthropic patched Claude Code 2.1.179 and OpenAI patched Codex 0.146.0 while Copilot had no fix per Air and Google will not patch deprecated Gemini CLI and points users to Antigravity, that GitHub rejects 40-hex branch names so default marketplace plugins are not exposed to that trick while Bitbucket and self-hosted setups can allow it, that Gemini CLI has a separate FETCH_HEAD path, that Claude Code and Codex default to background auto-update creating a zero-click path, that the issue was found in May 2026 and disclosed in June with no CVE and no known real-world attack as of September 18, and that Help Net Security framed it as the first AI-agent supply-chain vulnerability citing SkillJacking prior art and a fake-plugin test that reached more than 26,000 agents; unfinished patch rollout plus unfinished Copilot and Gemini CLI exposure is not already AI coding agents safe forever and not already every install owned forever
By the Numbers
2.1.179 / 0.146.0
THN: Claude Code and Codex patched versions; Copilot unfixed per Air; Gemini CLI deprecated without patch
May-June 2026
Found in May and disclosed in June; no CVE and no known real-world attack as of September 18
26,000+
Help Net Security citing earlier fake-plugin test reach across AI coding agents
Synthesized from 3 sources click any to read the original

The Hacker News reported September 18, 2026 that Air Security documented Plugin4Shell, a SHA-pinning bypass affecting Claude Code, Codex, GitHub Copilot, and Gemini CLI. Swati Khandelwal's coverage said Anthropic patched Claude Code in 2.1.179, OpenAI patched Codex in 0.146.0, that Copilot had no fix per Air as of that report, and that Google will not patch the deprecated Gemini CLI and instead points users to migrate to Antigravity. GitHub rejects 40-hex branch names, so default GitHub marketplace plugins are not exposed to the branch-name trick, while Bitbucket and self-hosted setups can allow it. Gemini CLI has a separate FETCH_HEAD mechanism. Claude Code and Codex default to background auto-update, creating a zero-click path if a malicious update lands. The issue was found in May 2026 and disclosed in June; as of September 18 there was no CVE and no known real-world attack per The Hacker News. Help Net Security's Sinisa Markovic framed Plugin4Shell as the first supply-chain vulnerability of the AI agent ecosystem, noting plugins inherit employee reach, citing prior SkillJacking research on 925 skills across about 134,000 agents, and a fake-plugin test that reached more than 26,000 agents. Marketplace fixes alone cannot close the hole; agent updates are required. Those are unfinished patch-rollout facts plus unfinished Copilot and Gemini CLI exposure facts. They are not proof AI coding agents are already safe forever, and they are not proof every install is already owned forever.

That is an unfinished disclosure layered on unfinished vendor patch coverage. It is not a finished forever agents-safe certificate, and it is not a finished forever every-install-owned certificate.

## What They Reported

The Hacker News framed Plugin4Shell as a SHA-pinning bypass on major AI coding agents. Named vendor status said Anthropic shipped Claude Code 2.1.179, OpenAI shipped Codex 0.146.0, Copilot remained unfixed per Air, and Google will not patch deprecated Gemini CLI while urging migration to Antigravity. Platform detail said GitHub's rejection of 40-hex branch names blocks the branch-name trick for default marketplace plugins, while Bitbucket and self-hosted environments remain more open, and Gemini CLI uses a separate FETCH_HEAD path. Zero-click risk was tied to background auto-update defaults in Claude Code and Codex. Timeline detail said discovery in May 2026, disclosure in June, no CVE as of September 18, and no known real-world attack. Help Net Security called it the first supply-chain vulnerability of the AI agent ecosystem, stressed that plugins inherit employee reach, and cited SkillJacking prior art plus a fake-plugin test that reached more than 26,000 agents. Air Security and Help Net Security both stressed that marketplace policy alone is not enough and that agent updates are required. Named journalism published unfinished patch status and unfinished Copilot and Gemini CLI exposure. It did not publish that AI coding agents were already safe forever or that every install was already owned forever.

Security feeds often compress "first AI-agent supply-chain vuln" into "every install already owned forever," or compress Anthropic and OpenAI patches into "AI coding agents already safe forever." Both habits flatten what The Hacker News, Help Net Security, and Air Security published: unfinished vendor remediation and unfinished Copilot and Gemini CLI exposure, not finished forever safety and not finished forever total ownership.

## The Correction

Three corrections are required at once.

First, treating Anthropic's Claude Code 2.1.179 patch and OpenAI's Codex 0.146.0 patch as proof AI coding agents are already safe forever invents finished forever safety from unfinished rollout. Two vendors shipping fixes is a real unfinished remediation signal. It is still not AI coding agents already safe forever while Copilot remains unfixed per Air, while Gemini CLI is deprecated without a patch, and while Bitbucket and self-hosted paths remain more exposed than GitHub marketplace defaults.

Second, treating Plugin4Shell, zero-click auto-update defaults, SkillJacking scale, and a fake-plugin test that reached more than 26,000 agents as proof every install is already owned forever invents finished forever compromise from unfinished research and unfinished disclosure. The Hacker News reported no known real-world attack as of September 18 and no CVE yet. Unfinished research severity is not already every install owned forever, and unfinished research severity is not already AI coding agents safe forever.

Third, treating GitHub's 40-hex branch-name rejection, Gemini CLI's separate FETCH_HEAD mechanism, marketplace-cannot-fix-alone guidance, and May-to-June find-and-disclose timing as proof either that agents are already safe forever or that every install is already owned forever invents finished end-states from unfinished platform differences. Platform mitigations and migration advice are real unfinished hygiene work. Neither converts partial patches into finished forever safety, and neither converts a disclosed bypass without known exploitation into finished forever ownership of every install.

Accurate language therefore holds three layers apart. Layer one: September 18, 2026 The Hacker News, Help Net Security, and Air Security reported Plugin4Shell as a SHA-pinning bypass across Claude Code, Codex, GitHub Copilot, and Gemini CLI. Layer two: Claude Code 2.1.179 and Codex 0.146.0 patched; Copilot no fix per Air; Google will not patch deprecated Gemini CLI and points to Antigravity; GitHub rejects 40-hex branch names for default marketplace plugins; Bitbucket and self-hosted allow more risk; Gemini CLI FETCH_HEAD path; zero-click via auto-update defaults; found May 2026, disclosed June; no CVE and no known real-world attack as of September 18; SkillJacking prior and fake-plugin reach cited; marketplace cannot fix alone. Layer three: unfinished patch rollout plus unfinished Copilot and Gemini CLI exposure is not already AI coding agents safe forever and not already every install owned forever.

## Why This Matters

AI-agent security headlines overreact because "first supply-chain vuln" and "zero-click" travel faster than the difference between unfinished patch rollout and finished forever safety, and faster than the difference between unfinished research disclosure and finished forever ownership of every install.

False already-safe claims confuse developers into skipping version checks, migration off deprecated Gemini CLI, and scrutiny of Bitbucket or self-hosted plugin pins. False already-every-install-owned claims erase the no-known-attack reporting window and convert unfinished research into finished mass-compromise theater. Accurate coverage can report a real SHA-pinning bypass and unfinished Copilot and Gemini CLI exposure without inventing finished forever safety or finished forever ownership.

NewsCorrections technology rule: unfinished patch rollout and unfinished Copilot and Gemini CLI exposure are not already AI coding agents safe forever and not already every install owned forever.

## Key Takeaways

Read the original from Thehackernews
View the source article we corrected
Source Bias Analysis
LEFT
45%
RIGHT
20%
NewsCorrections: 0% Bias Analyzed from 3 sources
See What We Corrected +
What We Corrected
Original from Thehackernews
“Unfinished patch rollout and unfinished Copilot and Gemini CLI exposure are not already AI coding agents safe forever and not already every install owned forever”
NewsCorrections Version
“On September 18, 2026 The Hacker News reported Air Security's Plugin4Shell SHA-pinning bypass on Claude Code, Codex, GitHub Copilot, and Gemini CLI, that Anthropic patched Claude Code 2.1.179 and OpenAI patched Codex 0.146.0 while Copilot had no fix per Air and Google will not patch deprecated Gemini CLI and points users to Antigravity, that GitHub rejects 40-hex branch names so default marketplace plugins are not exposed to that trick while Bitbucket and self-hosted setups can allow it, that Gemini CLI has a separate FETCH_HEAD path, that Claude Code and Codex default to background auto-update creating a zero-click path, that the issue was found in May 2026 and disclosed in June with no CVE and no known real-world attack as of September 18, and that Help Net Security framed it as the first AI-agent supply-chain vulnerability citing SkillJacking prior art and a fake-plugin test that reached more than 26,000 agents; unfinished patch rollout plus unfinished Copilot and Gemini CLI exposure is not already AI coding agents safe forever and not already every install owned forever”
Source: Thehackernews • Bias neutralized • Language corrected
Go Deeper
+

+

+

Test Your Mind · from the makers of NewsCorrections

Real World IQ

How smart are you really? The most comprehensive IQ assessment ever built, from Guinness World Records Puzzle Master Timothy E. Parker.

Take the Test →