Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched

Sep 18, 2026 - 11:00
Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched

Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same reach into a company’s systems and data as the employee running the agent, according to AIR. “It is the first supply chain vulnerability of the AI agent ecosystem,” the researchers said. “Anyone running a major coding agent that installs plugins from a marketplace is exposed. The exposure … More

The post Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched appeared first on Help Net Security.