Plugin4Shell zero-click RCE in Claude Code, Codex and Copilot exposes the agent authorization gap

docybo · reddit · 2026-09-20

Two developments days apart outline a structural gap in agent security:

Plugin4Shell (AIR Security, disclosed Sept 17)

NIST IR 8587 (finalized Sept 15, with CISA's JCDC)

Core argument: "Token hardening assumes the token holder is a known, bounded actor" (Yih Khai Wong, IDC). A valid credential proves identity or access — not that this action against this target under current policy was authorized. The author asks whether correct IAM/PDP/PEP deployment solves this, or whether a missing enforcement primitive sits between an agent having access and being authorized to act.

Related event: Plugin4Shell Zero-Click RCE Hits Major Coding Agents(2 posts)→

Original post →

More from coding & agent

coding & agent channel →