Malicious .git configs can make Claude, Codex, Cursor AI agents run attacker code
jedisct1 · x · 2026-09-03
Manifold Security disclosed eight flaws across seven CLI AI coding agents where a repo's own Git config (e.g. core.fsmonitor) names a command the agent executes on the developer's machine—running as the user, outside the sandbox, with no approval prompt. Four flaws were unpatched at disclosure.
- Exploitation requires the repo to arrive as files with its .git directory intact (shared archive, sync folder, USB); a normal clone is safe
- Fixed: goose, Claude Code, Cursor. Still executing repo-supplied commands on retest: Hermes Agent, Qwen Code, Grok Build, and a second Claude Code path
- Payload fires before workspace-trust acceptance (Claude Code, Hermes), before auth (Qwen Code), or on first keystroke (Grok Build)
- OpenAI issued three CVEs for the same class in Codex, noting the helper can read, change, or delete user files
More from coding & agent
- Hidden-bug eval across 105 issues: Fable 5.1 finds 43, none fixes all — cost per model compared — PawelHuryn · 2026-09-03
- Indie author builds an agent-native distribution layer for his novel with A2A endpoints — patternflow · 2026-09-03
- Bezalel gives AI agents memory, email, money and a cloud desktop behind one MCP URL — Rasmic · 2026-09-03
- jjk-explain turns any concept into a Jujutsu Kaisen-style explainer video with one Claude Code command — teortaxesTex · 2026-09-03
- A 'culture agent' fine-tunes Japanese legal phrasing in academic writing workflow — KarlMuth · 2026-09-03
- He quarantined pre-1996 sources to build a 'clone' of Prof. Milhaupt as a sounding board — KarlMuth · 2026-09-03