AI Agents Vulnerable to Malicious Git Configurations

AI Agents Vulnerable to Malicious Git Configurations

First seen 2 Sep 2026, 14:46 UTC Heise.DeThehackernewswww.manifold.securitygithub.comwww.sonarsource.com 54.9

Article Content

Browse articles
ThreatCluster

Manifold Security disclosed vulnerabilities in AI coding agents that allow malicious Git configurations to execute commands on a developer's machine with full user privileges. The attack vector exploits the .git/config file in repositories, enabling commands to run without user approval or sandboxing. Affected agents include Claude Code, Codex, Cursor, Hermes Agent, Qwen Code, and Grok Build, with four still unpatched as of September 1, 2026. OpenAI has published CVE-2026-19592 for Codex, highlighting similar vulnerabilities. The attack requires the malicious repository to be delivered as a file, not through standard Git operations like clone or pull. Developers are advised to inspect .git/config files for suspicious commands. Manifold's findings indicate a broader pattern of vulnerability across more agents than initially named. Fixes have been released for some agents, but others remain vulnerable.

Key Points: • Malicious Git configurations can execute commands without user approval. • Four AI agents remain unpatched despite known vulnerabilities. • Developers should inspect .git/config files for suspicious entries.

Timeline

2021-12-15
CVE-2021-43891 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2022-02-25
CVE-2022-24346 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-29
CVE-2026-55607 published
CVE-2026-55607 was published, detailing vulnerabilities in AI coding agents.
Thehackernews
2026-08-10
CVE-2026-72718 published
CVE-2026-72718 was published, adding to the list of vulnerabilities affecting AI agents.
Thehackernews
2026-09-01
OpenAI publishes CVE-2026-19592
OpenAI disclosed CVE-2026-19592 for Codex, confirming similar vulnerabilities in AI agents.
Thehackernews
2026-09-02
Manifold Security discloses vulnerabilities
Manifold Security disclosed multiple vulnerabilities in AI agents, detailing the attack vector and affected systems.
Heise.De