Published September 1, 2026 ยท Added September 3, 2026

GitSpawn: A Single Flaw Lets Untrusted Repos Run Code in Claude Code, Codex, Cursor, and Grok

Manifold Security disclosed GitSpawn, a class of flaws where AI coding agents automatically run Git commands that honor malicious local repository configuration, enabling untrusted repos to execute code before user prompts or workspace approval; several open-source agents were affected.

Manifold Security disclosed GitSpawn, a class of flaws where AI coding agents automatically run Git commands that honor malicious local repository configuration, enabling untrusted repos to execute code before user prompts or workspace approval; several open-source agents were affected.

Read the original story.

Source: Manifold