PoC public Claude Code Manifold Security ai-ml Codex CLI Anthropic
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
CVE Tools coverage
Manifold Security has published details on a vulnerability class dubbed Git Spawn, affecting command-line AI coding agents from Anthropic, OpenAI, Cursor, and others. By exploiting the core.fsmonitor Git configuration, attackers can embed commands in a repository that execute as the user without sandboxing or approval prompts when the agent initializes. While patches have been released for goose, Claude Code, and Cursor, Manifold confirms that Hermes Agent, Qwen Code, and Grok Build remain vulnerable as of September 1. Affected CVEs include CVE-2026-19592 for Codex and CVE-2026-72718 for goose.