Back to News
Threat Intelligence

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

Cyber RTSeptember 3, 20263 min read
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

Manifold Security identified eight security flaws in seven AI coding agents, with four still unpatched. These vulnerabilities allow repository-supplied commands to execute outside the agent's sandbox without user approval, requiring the repository's .git directory to remain intact. Fixes were released for some agents, but others, including Hermes Agent and Qwen Code, remain vulnerable. OpenAI and other companies have issued advisories, yet some issues persist. Users are advised to inspect .git/config and disable core.fsmonitor by default to mitigate risks.

Manifold Security has revealed eight security vulnerabilities across seven command-line AI coding agents, with four of these flaws remaining unpatched at the time of publication. These vulnerabilities allow a repository's Git configuration to execute commands on a developer's machine without user approval, posing a significant security risk. The exploitation requires the repository to be transferred with its .git directory intact, which can be facilitated through shared archives, drives, sync folders, or USB sticks, unlike a typical clone operation. Fixes have been implemented for some agents, including goose, Claude Code, and Cursor. However, others like Hermes Agent, Qwen Code, Grok Build, and a secondary path in Claude Code remain vulnerable. OpenAI has also published three CVEs related to similar vulnerabilities in its Codex, attributed to different research groups. These issues allow attacker-controlled code to run with user privileges, potentially compromising user files and resources. The vulnerabilities are linked to Git's core.fsmonitor setting, which runs commands to identify changed files. These commands are executed by the agents in the background to determine the current branch and file changes, leaving the repository's configuration untouched. Manifold's findings, published under the name GitSpawn, highlight a pattern of vulnerabilities in more agents than those explicitly named. Several agents and versions are affected by these vulnerabilities. For instance, goose versions prior to 1.44.0 were vulnerable until a fix was released in version 1.44.0. Similarly, various versions of Codex CLI and Codex Desktop for macOS and Windows have been patched. However, vulnerabilities in Claude Code, Hermes Agent, Qwen Code, and Grok Build remain unaddressed, with fixes pending. The vulnerabilities have been recognized by GitHub, which assigned a CVSS base score of 7.0 to one of the findings. The issue allows malicious code execution without user prompts or approvals, posing a severe risk. Previous reports by Sonar and other researchers have noted similar vulnerabilities in other platforms, highlighting the widespread nature of these security flaws. Manifold's reports indicate that some findings were duplicates of earlier independent discoveries. For example, a vulnerability in Claude Code was reported and fixed within days, but other paths remain vulnerable. The Hacker News confirmed that some advisories, such as those for Claude Code and Qwen Code, have not been published, leaving users in the dark about the status of these vulnerabilities. Despite the severity of these vulnerabilities, there have been no reported exploitations. Security experts advise users to inspect Git configurations before opening directories with agents and to disable certain Git settings globally to mitigate risks. Vendors are also encouraged to strip configurations on background calls to prevent exploitation. In conclusion, the disclosed vulnerabilities highlight significant security risks in AI coding agents, emphasizing the need for prompt patches and user vigilance. Users and vendors must take proactive measures to secure their systems against potential exploits, leveraging available advisories and updates to protect against these vulnerabilities.