{"id":61380,"date":"2026-09-17T22:42:29","date_gmt":"2026-09-17T22:42:29","guid":{"rendered":"https:\/\/www.theregister.com\/a\/5297335"},"modified":"2026-09-17T22:42:29","modified_gmt":"2026-09-17T22:42:29","slug":"ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\/","title":{"rendered":"AI coding agents&#8217; 0-click RCE flaw could hand attackers keys to the kingdom"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/image.theregister.com\/5297339.jpg?imageId=5297339&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\" class=\"ff-og-image-inserted\"><\/div>\n<div data-element-guid=\"d11159dd-82a3-4c53-901c-d41dec75505c\" readability=\"31.085714285714\"> <a data-tag=\"security\" href=\"https:\/\/www.theregister.com\/tag\/security\" class=\"lab-article-section-link\"> <\/p>\n<p class=\" lab-article-section lab-article-section-top \"> security <\/p>\n<p> <\/a> <\/p>\n<p class=\"subtitle below\"> Plugin4Shell attack affects all the major coding agents, researchers say <\/p>\n<\/p><\/div>\n<div data-element-guid=\"4c9dc5d9-c886-4348-bf4a-01d0dc71377d\" readability=\"138.29637305699\"> <!-- placeholder(#1) --> <\/p>\n<p>A zero-click vulnerability that allows remote code execution affects all of the major AI coding agents &#8211; Anthropic\u2019s Claude Code, OpenAI\u2019s Codex, Google&#8217;s Gemini CLI, Microsoft\u2019s Copilot, and Microsoft-owned GitHub Copilot &#8211; and could give attackers full access to every asset and piece of data that the agent can reach, researchers say.<\/p>\n<p>The exploit, dubbed \u201cPlugin4Shell,\u201d is a \u201cfirst-of-its-kind AI supply-chain attack,\u201d according to threat hunters at Air, a security startup focused on protecting enterprise AI agents.<\/p>\n<p>Instead of targeting the model or agent, Plugin4Shell attacks trusted marketplaces that host plugins for major coding agents. Such attacks could therefore reach millions of users and machines, the researchers said.<\/p>\n<p>Almost <a href=\"https:\/\/news.microsoft.com\/ai-in-action\/\" target=\"_blank\" rel=\"nofollow\">90 percent<\/a>&nbsp;of Fortune 500 companies use Copilot, according to Microsoft, which also happens to be one of the two that didn\u2019t ship a patch for the flaw.<\/p>\n<p>\u201cThe fix has to ship in the agent, and updating is the only complete mitigation where one exists,\u201d Air researchers Or Nevo, Dor Granat, and Niv Hoffman <a href=\"https:\/\/www.air.security\/blog-posts\/plugin4shell\" target=\"_blank\" rel=\"nofollow\">said<\/a> in a Thursday report.<\/p>\n<p>The Air team reported the security issue to all four vendors in June, and both Anthropic and OpenAI patched it in Claude Code 2.1.179 and Codex 0.146.0, respectively.<\/p>\n<p>Google has <a href=\"https:\/\/developers.googleblog.com\/an-important-update-transitioning-gemini-cli-to-antigravity-cli\/\" target=\"_blank\" rel=\"nofollow\">deprecated the Gemini CLI<\/a>, and therefore told Air it will not patch, so every install remains vulnerable. Google does, however, suggest users migrate to its newer Antigravity agentic development environment, which is protected from this attack.<\/p>\n<p>Microsoft didn\u2019t fix the flaw in Copilot. However, a GitHub spokesperson told us the Plugin4Shell attacks do not affect GitHub.<\/p>\n<p>\u201cTo prevent abuse of SHAs, GitHub does not allow users to create branch or tag names that resemble commit SHAs,\u201d the spokesperson said. \u201cThis mitigation ensures the reported vulnerability cannot be exploited on GitHub.\u201d<\/p>\n<p>The Air researchers said that the GitHub mitigation isn\u2019t sufficient to defeat Plugin4Shell attacks. This is \u201cbecause marketplaces can also be hosted in other platforms such as Bitbucket,\u201d the team told <span class=\"italic m-italic \" data-lab-italic=\"italic\">The Register.<\/span>&nbsp;<\/p>\n<p>\u201cMicrosoft Copilot is also still vulnerable because it supports marketplaces from such platforms as well, which exposes it to the vulnerability,\u201d the researchers added. \u201cAir also reported the same to Microsoft (since June), but unfortunately due [to] the amount of disclosure volume they\u2019re currently getting we didn\u2019t get a response from them.\u201d<\/p>\n<p>Redmond did not immediately respond to <span class=\"italic m-italic \" data-lab-italic=\"italic\">The Register<\/span>\u2019s request for comment.<\/p>\n<p>The security hole sits in how agents enforce marketplaces\u2019 SHA-pinning mechanism, which locks agent plugins and skills to a specific, immutable commit hash instead of a mutable reference like a version tag or branch name.<\/p>\n<p>This aims to prevent supply chain attacks: If a public skill repository is compromised, your AI agent will continue running the same, audited code hash it used when you pinned it instead of automatically pulling new, malicious payloads.<\/p>\n<p>The researchers describe the vulnerability as a \u201cplugin SHA-pinning bypass.\u201d<\/p>\n<p>\u201cThe agent checks out the exact commit the marketplace pinned but never verifies it landed there, so an attacker who controls the plugin&#8217;s repo makes the checkout resolve to malicious code while the pin still looks honored,&#8221; Nevo, Granat, and Hoffman wrote. \u201cThe result is zero-click remote code execution.\u201d<\/p>\n<p>Agents\u2019 plugin auto-update feature makes this a zero-click attack. When a pinned commit is swapped upstream, the agent\u2019s plugin gets replaced with a malicious version, and both Claude and Codex automatically update installed plugins by default.<\/p>\n<p>The researchers say an attacker could abuse this flaw in two ways. In one scenario, the attacker submits a benign plugin to a trusted marketplace, the plugin passes review, and then the attacker later replaces the benign content with malicious code.<\/p>\n<p>The second attack involves hijacking a legitimate author&#8217;s repository and then pushing the malicious version onto every agent that has it installed &#8211; essentially bypassing the SHA pinning safety mechanism that exists to stop this type of supply chain attack. The team demonstrates this type of takeover in their earlier <a href=\"https:\/\/vimeo.com\/1206553501?fl=pl&amp;fe=sh\" rel=\"nofollow\">SkillJacking<\/a> and <a href=\"https:\/\/vimeo.com\/1214324682?fl=pl&amp;fe=sh\" rel=\"nofollow\">RepoJacking<\/a> proof-of-concept attacks.&nbsp;<\/p>\n<p>\u201cTogether, the chain is proven end to end &#8211; takeovers happen at scale, and Plugin4Shell defeats the mechanism built to contain them,\u201d the researchers wrote. \u00ae<\/p>\n<\/p><\/div>\n<p><img decoding=\"async\" src=\"https:\/\/image.theregister.com\/?imageId=5297339&#038;width=800\">READ MORE <a href=\"https:\/\/www.theregister.com\/security\/2026\/09\/17\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\/5297335\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Plugin4Shell attack affects all the major coding agents, researchers say READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[307],"class_list":["post-61380","post","type-post","status-publish","format-standard","hentry","category-the-register","tag-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>AI coding agents&#039; 0-click RCE flaw could hand attackers keys to the kingdom 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"AI coding agents&#039; 0-click RCE flaw could hand attackers keys to the kingdom 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-17T22:42:29+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/image.theregister.com\/5297339.jpg?imageId=5297339&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"AI coding agents&#8217; 0-click RCE flaw could hand attackers keys to the kingdom\",\"datePublished\":\"2026-09-17T22:42:29+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\\\/\"},\"wordCount\":719,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/image.theregister.com\\\/5297339.jpg?imageId=5297339&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\",\"keywords\":[\"Security\"],\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\\\/\",\"name\":\"AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/image.theregister.com\\\/5297339.jpg?imageId=5297339&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\",\"datePublished\":\"2026-09-17T22:42:29+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\\\/#primaryimage\",\"url\":\"https:\\\/\\\/image.theregister.com\\\/5297339.jpg?imageId=5297339&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\",\"contentUrl\":\"https:\\\/\\\/image.theregister.com\\\/5297339.jpg?imageId=5297339&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/security\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"AI coding agents&#8217; 0-click RCE flaw could hand attackers keys to the kingdom\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\/","og_locale":"en_US","og_type":"article","og_title":"AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2026-09-17T22:42:29+00:00","og_image":[{"url":"https:\/\/image.theregister.com\/5297339.jpg?imageId=5297339&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"AI coding agents&#8217; 0-click RCE flaw could hand attackers keys to the kingdom","datePublished":"2026-09-17T22:42:29+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\/"},"wordCount":719,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\/#primaryimage"},"thumbnailUrl":"https:\/\/image.theregister.com\/5297339.jpg?imageId=5297339&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","keywords":["Security"],"articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\/","url":"https:\/\/www.threatshub.org\/blog\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\/","name":"AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\/#primaryimage"},"thumbnailUrl":"https:\/\/image.theregister.com\/5297339.jpg?imageId=5297339&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","datePublished":"2026-09-17T22:42:29+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\/#primaryimage","url":"https:\/\/image.theregister.com\/5297339.jpg?imageId=5297339&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","contentUrl":"https:\/\/image.theregister.com\/5297339.jpg?imageId=5297339&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Security","item":"https:\/\/www.threatshub.org\/blog\/tag\/security\/"},{"@type":"ListItem","position":3,"name":"AI coding agents&#8217; 0-click RCE flaw could hand attackers keys to the kingdom"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61380","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=61380"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61380\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=61380"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=61380"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=61380"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}