Skip to content

GitSpawn Flaws Let Malicious Repositories Execute Code in Claude Code, Codex, Cursor, and Grok

Cybersecuritynews Guru Baran September 2, 2026

A newly disclosed class of vulnerabilities, dubbed GitSpawn, allows a booby-trapped repository to silently execute code on a developer’s machine the moment it is opened with an AI coding agent, no prompt typed, no approval clicked, and in some cases before the user has even authenticated. Security researchers at Manifold Security found the flaw while […]

Extracted Entities

Campaigns (1)

Companies (1)