Malicious .git Configs Can Make AI Agents Run Attacker Code

Executive Summary

Manifold Security uncovered eight security flaws in seven command‑line AI coding agents (Claude, Codex, Cursor, etc.). A malicious repository’s .git/config can specify a command that the agent automatically executes on the developer’s machine, running as the user outside the agent’s sandbox and without any approval prompt. Exploitation requires the repository to be cloned, and four of the eight vulnerabilities remain unpatched at the time of disclosure.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-02T14:06:59+00:00 - Category: threat-intel

Original Description: Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive

"When you arise in the morning, think of what a precious privilege it is to be alive � to breathe, to think, to enjoy, to love."

— Marcus Aurelius
Source: The Hacker News