Cybersecurity · September 3, 2026
Security researchers at Manifold Security found eight flaws spanning seven command-line AI coding assistants, including Claude, Codex, and Cursor, where a repository's Git configuration file can specify a command the agent executes automatically. Because the command runs with the developer's own permissions and skips any confirmation step, simply opening a booby-trapped repo could hand an attacker code execution on the machine. Four of the eight issues remained unpatched at the time of disclosure.
// source: thehackernews.com ↗