On September 2, 2026, security researchers at Manifold Security disclosed GitSpawn, a class of vulnerabilities affecting AI coding agents including Claude Code, Codex, Cursor, and Grok. Attackers can exploit malicious repository configurations to execute arbitrary code on developers' machines with user privileges.
5 reportsother
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
Security researchers at Manifold Security disclosed GitSpawn, a class of vulnerabilities that can let a malicious repository make AI coding agents execute attacker-controlled code on a developer’s machine as soon as the project is opened, without a prompt or approval click [heise.de#1][cybersecuritynews.com#1][thehackernews.com#1]. The affected tools named in the reports include Claude Code, Codex
From yesterday: Manifold Security: GitSpawn: A Single Flaw Lets Untrusted Repos Run Code in Claude Code, Codex, Curser and Grok https://www. manifold.security/blog/ai-codi ng-agents-git-hijack More: The Hacker News: Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code https:// thehackernews.com/2026/09/mali cious-git-configs-can-make-claude.html @ thehackern
🤖 Manifold Security discloses 8 flaws in 7 AI coding agents (Claude, Codex, Cursor, ...): a malicious .git config in a repository makes the agent run attacker commands on the dev machine — as the user, outside the sandbox, without an approval prompt. 4 of 8 still unpatched. 🔗 https:// thehackernews.com/2026/09/mali cious-git-configs-can-make-claude.html # Exploit # AISecurity # CyberSec
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code https:// thehackernews.com/2026/09/mali cious-git-configs-can-make-claude.html