Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

Cybersecurity · September 3, 2026

Cybersecurity·thehackernews.com

Security researchers at Manifold Security found eight flaws spanning seven command-line AI coding assistants, including Claude, Codex, and Cursor, where a repository's Git configuration file can specify a command the agent executes automatically. Because the command runs with the developer's own permissions and skips any confirmation step, simply opening a booby-trapped repo could hand an attacker code execution on the machine. Four of the eight issues remained unpatched at the time of disclosure.

// source: thehackernews.com ↗

Back to Blog