Malicious .git configs make Claude Code, Codex, Cursor run attacker code pre-trust-prompt
Thionne_WTZ · x · 2026-09-03
Manifold Security has disclosed 8 flaws across 7 CLI AI coding agents where a repo's own .git/config (e.g. core.fsmonitor) names a command the agent executes with user privileges — outside the sandbox and with no approval prompt.
Key facts:
- Exploitation requires the repo to arrive as files with .git intact (archives, shared drives, sync folders, USB); a normal clone is safe
- On Claude Code and Hermes Agent the payload fires before the workspace-trust prompt; on Qwen Code before auth, on Grok Build at the first keystroke
- Patched: goose, Claude Code, Cursor. Still unpatched at publication: Hermes Agent, Qwen Code, Grok Build, and a second Claude Code path
- OpenAI shipped three CVEs the same day for the identical class in Codex
More from coding & agent
- One-person company in 2026 = you plus four Grok bots running marketing — PrajwalTomar_ · 2026-09-03
- Rival AI agents: cross-vendor model review catches what self-review misses — rseroter · 2026-09-03
- Web Draw: MCP server reads pages as text instead of screenshots, Amazon page ~750 tokens — ahstanin · 2026-09-03
- Let Claude write its own /compact prompt and follow-up message — zsakib_ · 2026-09-03
- VibeCAD + McMaster parts search? Early impressions say Fable 5.1 is quite good — burhop · 2026-09-03
- Claude Code Opus 5 Auto Mode hijacked via prompt injection with up to 80% success rate — bibryam · 2026-09-03