chiprook
← Security
SecurityOctober 11, 2026, 22:35

GitSpawn: one line in .git/config turns coding agents into command runners

Manifold Security disclosed GitSpawn — eight flaws across seven CLI coding agents, four still unpatched at publication. A malicious repo uses the core.fsmonitor key in local .git/config to make the agent run an attacker command outside its sandbox and without an approval prompt.

GitSpawn: one line in .git/config turns coding agents into command runners
#Claude#Cursor#Codex#Git
Read next
Software

GitHub rewrites Git storage to handle AI agent surge

Software

Cursor Uses S3 WAL to Scale Git Storage Past 300 Pushes per Second

Security

Semicolon in a Codex branch name leaked GitHub token via command injection

Security

Researchers escape OpenAI Codex sandbox to run commands on host