Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
AI Summary
Manifold Security identified eight security flaws across seven command-line AI coding agents that allow malicious Git configurations to execute attacker-controlled code on developers' machines without user approval or sandboxing. The vulnerabilities stem from agents executing repository-supplied Git commands—specifically via the core.fsmonitor setting—during background operations like git status or git diff, enabling pre-trust code execution. Several agents, including Hermes Agent, Qwen Code, Grok Build, and a secondary path in Claude Code, remain unpatched as of September 1, 2026. The issue affects how AI agents interact with local Git repositories, particularly when transferred via shared drives or archives preserving the .git directory.
AI-extracted · verify before operational use