Thehackernews
AI Agents Vulnerable to Malicious Git Configurations
Article Content
Manifold Security disclosed vulnerabilities in AI coding agents that allow malicious Git configurations to execute commands on a developer's machine with full user privileges. The attack vector exploits the .git/config file in repositories, enabling commands to run without user approval or sandboxing. Affected agents include Claude Code, Codex, Cursor, Hermes Agent, Qwen Code, and Grok Build, with four still unpatched as of September 1, 2026. OpenAI has published CVE-2026-19592 for Codex, highlighting similar vulnerabilities. The attack requires the malicious repository to be delivered as a file, not through standard Git operations like clone or pull. Developers are advised to inspect .git/config files for suspicious commands. Manifold's findings indicate a broader pattern of vulnerability across more agents than initially named. Fixes have been released for some agents, but others remain vulnerable.
Key Points: • Malicious Git configurations can execute commands without user approval. • Four AI agents remain unpatched despite known vulnerabilities. • Developers should inspect .git/config files for suspicious entries.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.