Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
The Hacker News
Read full postManifold Security revealed eight security vulnerabilities in seven AI coding agents where malicious .git configurations can execute attacker code on users' machines without prompts. Some agents like goose, Claude Code, and Cursor have patched the flaws, while others remain vulnerable. OpenAI also reported related CVEs for Codex, highlighting risks in subprocess commands triggered by Git settings.




