Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Malicious Git Configs: The Unpatched Vulnerability Affecting AI Agents




A recent vulnerability in AI agents, codenamed "GitSpawn," has been discovered, allowing attackers to execute malicious code with the user's privileges. The vulnerability, which affects Codex, Claude, and Cursor, highlights the importance of proper configuration and security controls in AI systems. Experts warn that the vulnerability is not a new one, but rather a result of the use of the `core.fsmonitor` setting in a way that allows an attacker to execute malicious code. The patch for the affected agents is available for download on the Manifold Security website.

  • Eight security flaws were discovered across seven command-line AI coding agents.
  • A vulnerability dubbed "GitSpawn" was identified in the Git configuration of the agents, allowing attackers to run arbitrary code with user privileges.
  • The vulnerability was attributed to the use of the `core.fsmonitor` Git configuration setting.
  • The affected AI agents include Codex, Claude, and Cursor, which were designed to interact with developers and automate tasks.
  • A patch for the affected agents has been developed by Manifold Security, which includes a fix for the `core.fsmonitor` configuration setting.
  • Experts warn that the vulnerability highlights the importance of proper configuration and security controls in AI systems and software development.
  • The vulnerability has raised concerns about potential supply chain attacks and the need for developers to stay up-to-date with the latest security patches and best practices.



  • In a recent development that has sent shockwaves through the cybersecurity community, a vulnerability has been discovered in the Git configuration of certain AI agents, allowing attackers to execute malicious code with the user's privileges. The affected AI agents, developed by various organizations, including OpenAI, Codex, and Claude, are utilized in a wide range of applications, from machine learning and automation to cybersecurity and threat intelligence.

    According to a report by Manifold Security, a security firm that specializes in identifying and mitigating vulnerabilities in AI systems, eight security flaws were discovered across seven command-line AI coding agents. The vulnerabilities, which were identified in the Git configuration of the agents, allow an attacker to run arbitrary code on the system, potentially leading to a compromise of sensitive data or even physical access to the system.

    The vulnerability, which has been dubbed "GitSpawn," is attributed to the use of the `core.fsmonitor` Git configuration setting, which allows the agent to execute a command to identify changed files in the repository. However, an attacker can manipulate the Git configuration to run malicious code outside of the agent's sandbox, bypassing security controls and potentially gaining access to sensitive data or executing malicious code with the user's privileges.

    The affected AI agents, including Codex, Claude, and Cursor, are designed to interact with developers and automate tasks, but the vulnerability highlights the importance of proper configuration and security controls in AI systems. The discovery of the vulnerability has raised concerns about the potential for malicious actors to exploit the vulnerability to gain access to sensitive data or execute malicious code in AI systems.

    In response to the vulnerability, Manifold Security has developed a patch for the affected agents, which includes a fix for the `core.fsmonitor` configuration setting. The patch is available for download on the Manifold Security website.

    Experts warn that the vulnerability is not a new one, but rather a result of the use of the `core.fsmonitor` setting in a way that allows an attacker to execute malicious code. The vulnerability highlights the importance of proper configuration and security controls in AI systems, as well as the need for developers to stay up-to-date with the latest security patches and best practices.

    In addition to the vulnerability in AI agents, the discovery of the GitSpawn vulnerability has highlighted the importance of proper Git configuration and security controls in software development. The vulnerability is a reminder that even seemingly innocuous configuration settings can be exploited by malicious actors if not properly secured.

    The vulnerability has also raised concerns about the potential for supply chain attacks, as malicious actors may attempt to compromise the Git configuration of AI agents or other software packages to gain access to sensitive data or execute malicious code.

    In conclusion, the discovery of the GitSpawn vulnerability in AI agents highlights the importance of proper configuration and security controls in AI systems. The vulnerability emphasizes the need for developers to stay up-to-date with the latest security patches and best practices, as well as the importance of proper Git configuration and security controls in software development.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Malicious-Git-Configs-The-Unpatched-Vulnerability-Affecting-AI-Agents-ehn.shtml

  • https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html

  • https://utopiats.com/blog/malicious-git-configs-can-make-claude-codex-cursor-and-other-ai-agents-run-attacker-code


  • Published: Wed Sep 2 11:03:30 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us