Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
OpenAir

OpenAir Vendor Cyber Rating & Cyber Score

openair.com

OpenAir started with a simple vision: that project-based organizations needed a more effective way to manage their key assets, namely their employees and their expertise. Just as ERP systems improved manufacturing operations, software could help service firms and internal service groups operate more effectively and profitably.


OpenAir A.I CyberSecurity Scoring

OpenAir
Company Information
Website:http://www.openair.com
Employees number:28
Number of followers:1,210
NAICS:5112
Industry Type:Software Development
Homepage:openair.com
OpenAir Risk Score (AI oriented)
Between 700 and 749
logo
OpenAirSoftware Development
Updated:
18/09/2026
749/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
✖ Insurance prefers TPRM score to calculate premium
OpenAir Global Score (TPRM)
xxxx
logo
OpenAirSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

OpenAirModerate
Current Score
749Ba (MODERATE)
01000
1 incidents
-3 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
749Before Incident
SEPTEMBER 2026
749Before Incident
AUGUST 2026
749Before Incident
JULY 2026
749Before Incident
JUNE 2026
749Before Incident
MAY 2026
751Before Incident
Vulnerability
01 May 2026 • OpenAir
Microsoft, OpenAI and Anthropic: Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched

Critical Zero-Click RCE Flaw Found in Major AI Coding Agents (Plugin4Shell)

748After Incident
CRITICAL-3
MICANTOPE1789727167
Critical Zero-Click RCE Flaw Found in Major AI Coding Agents Researchers at AIR (AI Incident Response) have uncovered a severe zero-click remote code execution (RCE) vulnerability, dubbed Plugin4Shell, affecting four leading AI coding agents: Claude Code, Codex, GitHub Copilot, and Gemini CLI. The flaw allows attackers to bypass SHA pinning a security mechanism designed to lock plugins to verified versions granting them the same access to systems and data as the user running the agent. ### How the Vulnerability Works The bug exploits weaknesses in how these agents verify pinned plugin commits. Normally, SHA pinning ensures that once a plugin passes review, its code cannot be altered without detection. However, AIR found that all four agents fail to confirm whether the checked-out code matches the pinned commit, enabling attackers to swap in malicious code while the pin appears intact. - Claude Code, Codex, and GitHub Copilot share a flaw tied to Git’s handling of branch names, where a branch can be named like a hash. - Gemini CLI has a separate issue in its commit-fetching process, leading to the same outcome. The attack is particularly dangerous because it is zero-click exploitable even on auto-updating plugins without user interaction. Since the vulnerability persists in background updates, already-installed plugins remain at risk. ### Attack Vectors AIR demonstrated two primary methods for exploitation: 1. Malicious Plugin Takeover – An attacker publishes a legitimate plugin, passes review, and later replaces it with malicious code. 2. Repository Hijacking – An attacker compromises a trusted plugin’s repository (as seen in AIR’s SkillJacking research, where 925 hijacked plugins reached 134,000 agents). ### Vendor Responses AIR disclosed the flaw to vendors in June 2026 after discovering it in May 2026: - Anthropic patched Claude Code (v2.1.179). - OpenAI fixed Codex (v0.146.0). - Microsoft has not released a patch for GitHub Copilot, leaving users exposed. - Google deprecated Gemini CLI entirely, advising users to migrate to Antigravity, a newer agent without the vulnerable plugin system. Since the issue lies within the agents themselves, marketplace protections alone are insufficient. The only complete fix requires vendor updates, leaving some users indefinitely vulnerable.
INCIDENT DETAILS -
TYPE
Zero-Click Remote Code Execution (RCE)
IMPACT
Claude CodeCodexGitHub CopilotGemini CLIOperational Impact: Potential unauthorized access to systems and data with user-level permissionsBrand Reputation Impact: Potential reputational damage to affected vendors (Anthropic, OpenAI, Microsoft, Google)
APRIL 2026
751Before Incident
MARCH 2026
751Before Incident
FEBRUARY 2026
751Before Incident
JANUARY 2026
751Before Incident
DECEMBER 2025
751Before Incident
NOVEMBER 2025
751Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for OpenAir ?
?
What was OpenAir's A.I Rankiteo Cyber Score in September 2026 ?
?
What was OpenAir's A.I Rankiteo Cyber Score in August 2026 ?
?
What was OpenAir's A.I Rankiteo Cyber Score in July 2026 ?
?
What was OpenAir's A.I Rankiteo Cyber Score in June 2026 ?
?
What was OpenAir's A.I Rankiteo Cyber Score in May 2026 ?
?
What was OpenAir's A.I Rankiteo Cyber Score in April 2026 ?
?
What was OpenAir's A.I Rankiteo Cyber Score in March 2026 ?
?
What was OpenAir's A.I Rankiteo Cyber Score in February 2026 ?
?
What was OpenAir's A.I Rankiteo Cyber Score in January 2026 ?
?
What was OpenAir's A.I Rankiteo Cyber Score in December 2025 ?
?
What was OpenAir's A.I Rankiteo Cyber Score in November 2025 ?
?
What is the average per-incident point impact on OpenAir's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with OpenAir ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view OpenAir's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?