< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-09-02T19:36:59+05:30

Security Vulnerability in AI Coding Agents Exploits Malicious .git Configurations

A security vulnerability allows malicious .git configurations to execute attacker code on AI coding agents like Claude, Codex, and Cursor. The flaw, present in seven agents with four unpatched at publication, leverages Git's fsmonitor feature to bypass security measures.

Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication.

The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive

Read original article

*** END OF TRANSMISSION ***