Malicious .git configs can make Claude, Codex, Cursor run attacker code

Manifold Security disclosed eight flaws across seven CLI AI coding agents where a repo's Git config names a command the agent runs as the user, outside the sandbox. Fixes shipped for goose, Claude Code, and Cursor; Hermes Agent, Qwen Code, Grok Build, and a second Claude Code path remained unpatched as of Sept 1.
2 sources
Cybersecurity by email
Get an email when there's news on Cybersecurity
No news that day, no email.
More stories today
- NYSE used Anthropic's Project Glasswing to find cyber flaws
- Cloudflare CEO says ready to block AI crawlers from millions of sites
- Napster CEO: Microsoft helps reinvent company with agentic AI
- Google shares 4 engineering patterns from AI Agents Challenge
- Anthropic launches commerce agent blueprint for Claude