VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews · rss_335721a8136cc299e91a1e581f90399c

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

Published Sep 2, 2026

Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication.

The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive

Affected AI Products

ai agent claude cursor
Get the weekly digest. Every Monday: top AI security stories of the week. Free.