GitSpawn: one line in .git/config turns coding agents into command runners
Manifold Security disclosed GitSpawn — eight flaws across seven CLI coding agents, four still unpatched at publication. A malicious repo uses the core.fsmonitor key in local .git/config to make the agent run an attacker command outside its sandbox and without an approval prompt.
- Eight flaws across seven CLI coding agents, four unpatched at publication
- Command runs as the user outside the agent sandbox and without approval
- Claude Code and Hermes Agent fire before the workspace-trust prompt
- Fixed: goose, Cursor, Codex and Claude Code's core.fsmonitor path 2.1.196
Read next
Software