
September 21, 2026 · Security
Four AI coding agents share a zero-click plugin vulnerability tracked in briefings as Plugin4Shell. Two of the affected products were still unpatched as of the September 21 roundups. The class of bug allows remote code execution through plugin handling without an explicit click from the developer.
Coding agents sit in a dangerous place: they read repositories, install extensions, and often run with the same privileges as a local toolchain. A shared plugin surface means one design mistake can span vendors that otherwise compete on models and UX.
The disclosure lands beside other offensive-AI headlines this month, including a white-hat chain that used a new Claude release to reach OpenAI-connected accounts. Together they show that agent tooling is now a primary attack path, not a side channel.
Teams that enabled third-party agent plugins should treat this as a patch-now event: disable untrusted plugins, confirm vendor advisories, and assume default-allow plugin stores are in scope.
Key takeaway A shared plugin flaw across four coding agents is a reminder that the agent runtime—not just the base model—is now critical infrastructure for software supply-chain risk.
Photo: Christina Morillo / Unsplash. Sources: AIToolsRecap; AI Weekly (Sept. 21, 2026).
