CybersecurityDev3 min reading time

GitSpawn: Untrusted repos can execute code via AI coding agents

Hacker News
Read full post
Researchers discovered that several AI coding agents execute git commands that can run arbitrary code from a repository's configuration without user approval, posing security risks when using untrusted repos. This vulnerability arises because git commands refresh their index using repository-specific settings like core.fsmonitor, which can specify executable commands.

More in Cybersecurity

Scoop: OpenAI faces GOP-led Senate investigation into Hugging Face breach

Covered by 2 sources

Chinese AI Giants Accused of Sending Millions of User Queries to U.S. Models

The Wall Street Journal
Cybersecurity6 min read

Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6

Covered by 2 sources