CVE Tools

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

The Hacker NewsBy The Hacker News

PoC publicClaude CodeManifold SecurityCodex CLI

Our summary

Manifold Security has published details on a vulnerability class dubbed Git Spawn, affecting command-line AI coding agents from Anthropic, OpenAI, Cursor, and others. By exploiting the core.fsmonitor Git configuration, attackers can embed commands in a repository that execute as the user without sandboxing or approval prompts when the agent initializes. While patches have been released for goose, Claude Code, and Cursor, Manifold confirms that Hermes Agent, Qwen Code, and Grok Build remain vulnerable as of September 1. Affected CVEs include CVE-2026-19592 for Codex and CVE-2026-72718 for goose.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store