CVE Tools
Back to feed
PoC public Claude Code Manifold Security ai-ml Codex CLI Anthropic

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

The Hacker News·By The Hacker News··6 min read
CVE Tools coverage

Manifold Security has published details on a vulnerability class dubbed Git Spawn, affecting command-line AI coding agents from Anthropic, OpenAI, Cursor, and others. By exploiting the core.fsmonitor Git configuration, attackers can embed commands in a repository that execute as the user without sandboxing or approval prompts when the agent initializes. While patches have been released for goose, Claude Code, and Cursor, Manifold confirms that Hermes Agent, Qwen Code, and Grok Build remain vulnerable as of September 1. Affected CVEs include CVE-2026-19592 for Codex and CVE-2026-72718 for goose.