Malicious .git configs make Claude Code, Codex, Cursor run attacker code pre-trust-prompt

Thionne_WTZ · x · 2026-09-03

Manifold Security has disclosed 8 flaws across 7 CLI AI coding agents where a repo's own .git/config (e.g. core.fsmonitor) names a command the agent executes with user privileges — outside the sandbox and with no approval prompt.

Key facts:

Related event: Malicious .git Config Vulnerabilities Let AI Coding Agents Run Attacker Code(2 posts)→

Original post →

More from coding & agent

coding & agent channel →