Thehackernews iconThehackernewsSep 2, 2026

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

Share this story

Send the public story page.

Useful takeaways from this story.

The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive

Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine,...

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication.

Details worth keeping

Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app