GitSpawn Vulnerabilities Allow Code Execution in AI Coding Agents

GitSpawn Vulnerabilities Allow Code Execution in AI Coding Agents

First seen 2 Sep 2026, 14:46 UTC Heise.DeThehackernewsgithub.comwww.sonarsource.comCybersecuritynews+4 69.8

Article Content

Browse articles
ThreatCluster

A series of vulnerabilities, termed GitSpawn, have been disclosed affecting multiple AI coding agents, including Claude Code, Codex, and Cursor. These flaws allow malicious Git configurations to execute arbitrary code on a developer's machine without user interaction or approval. The vulnerabilities were identified by Manifold Security and affect agents that run Git commands in the background before user authentication or trust prompts. As of September 1, 2026, several of these vulnerabilities remain unpatched, particularly in Hermes Agent, Qwen Code, and Grok Build. The vulnerabilities are linked to improper handling of Git configurations, specifically the core.fsmonitor setting. Affected versions include Claude Code 2.1.193 and earlier, Codex CLI 0.102.0 to 0.130.0, and Goose 1.41.0. Patches have been released for some tools, but many remain vulnerable. The issue is critical due to the potential for full system compromise, including access to sensitive credentials.

Key Points: • GitSpawn vulnerabilities allow arbitrary code execution in AI coding agents. • Affected tools include Claude Code, Codex, Cursor, and Goose, with some still unpatched. • Exploitation occurs via malicious Git configurations without user approval.

Ask AI about this cluster

Timeline

2021-12-15
CVE-2021-43891 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2022-02-25
CVE-2022-24346 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-29
CVE-2026-55607 published
Initial vulnerabilities related to GitSpawn were disclosed, affecting multiple AI coding agents.
Thehackernews
2026-08-10
CVE-2026-72718 published
Further vulnerabilities in AI coding agents were documented, expanding the scope of GitSpawn.
Cybersecuritynews
2026-09-01
Manifold Security confirms vulnerabilities
Manifold Security confirmed multiple vulnerabilities across AI coding agents, with some still unpatched.
Heise.De
2026-09-01
CVE-2026-19592 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-02
Patches released for some agents
Patches were released for Claude Code and Codex, but vulnerabilities in Hermes, Qwen, and Grok remain.
Sonarsource