Malicious .git configs can make Claude, Codex, Cursor AI agents run attacker code

jedisct1 · x · 2026-09-03

Manifold Security disclosed eight flaws across seven CLI AI coding agents where a repo's own Git config (e.g. core.fsmonitor) names a command the agent executes on the developer's machine—running as the user, outside the sandbox, with no approval prompt. Four flaws were unpatched at disclosure.

Related event: Malicious .git Config Vulnerabilities Let AI Coding Agents Run Attacker Code(2 posts)→

Original post →

More from coding & agent

coding & agent channel →