Thehackernews
GitSpawn Vulnerabilities Allow Code Execution in AI Coding Agents
Article Content
A series of vulnerabilities, termed GitSpawn, have been disclosed affecting multiple AI coding agents, including Claude Code, Codex, and Cursor. These flaws allow malicious Git configurations to execute arbitrary code on a developer's machine without user interaction or approval. The vulnerabilities were identified by Manifold Security and affect agents that run Git commands in the background before user authentication or trust prompts. As of September 1, 2026, several of these vulnerabilities remain unpatched, particularly in Hermes Agent, Qwen Code, and Grok Build. The vulnerabilities are linked to improper handling of Git configurations, specifically the core.fsmonitor setting. Affected versions include Claude Code 2.1.193 and earlier, Codex CLI 0.102.0 to 0.130.0, and Goose 1.41.0. Patches have been released for some tools, but many remain vulnerable. The issue is critical due to the potential for full system compromise, including access to sensitive credentials.
Key Points: • GitSpawn vulnerabilities allow arbitrary code execution in AI coding agents. • Affected tools include Claude Code, Codex, Cursor, and Goose, with some still unpatched. • Exploitation occurs via malicious Git configurations without user approval.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.