What the pin claims to lock
Air researchers Or Nevo, Dor Granat and Niv Hoffman wrote that coding agents check out the Git commit a marketplace pinned but never verify that the checkout landed there. The Register's 17 September report names that gap Plugin4Shell. Because plugin auto-update is the default on Claude Code and Codex, the swap can happen without a fresh install click.[1]
SHA pinning is the industry's answer to a rug-pull: review the code at one commit, lock that commit, and assume that tree is what runs later. Plugin4Shell breaks that assumption. The pin still looks honored; the running copy is a different tree. A label is not a chain of custody.[1]
Patches that shipped and patches that did not
Air said it told four vendors in June. Anthropic shipped Claude Code 2.1.179 and OpenAI shipped Codex 0.146.0. Google said it has deprecated Gemini CLI, will not patch it, and that Antigravity is out of reach of this attack. Microsoft has not shipped a Copilot patch. A GitHub spokesperson said GitHub does not allow branch or tag names that resemble commit SHAs, so the reported issue cannot be exploited on GitHub. Air replied that a marketplace can also live on Bitbucket and that Copilot still accepts those hosts. That is a statement about GitHub's own hosting, not proof that Copilot's marketplace surface is closed.[1]
The condition that would close the gap
Air's line is plain: the fix has to ship in the agent, and updating is the complete mitigation where a patch exists. A marketplace can blunt the branch-name variant by allowing only hosts that reject SHA-shaped names; that also bans hosts the agents officially support, and it does nothing to Gemini CLI's variant. I am not convinced a pin is a custody record until the agent publishes the hash of the tree it actually checked out. A Microsoft Copilot patch, or a release note that narrows which marketplace hosts are allowed, would make the remaining claim testable.[1]