Manifold Security disclosed GitSpawn, a class of flaws where AI coding agents automatically run Git commands that honor malicious local repository configuration, enabling untrusted repos to execute code before user prompts or workspace approval; several open-source agents were affected.
GitSpawn: A Single Flaw Lets Untrusted Repos Run Code in Claude Code, Codex, Cursor, and Grok
Manifold Security disclosed GitSpawn, a class of flaws where AI coding agents automatically run Git commands that honor malicious local repository configuration, enabling untrusted repos to execute code before user prompts or workspace approval; several open-source agents were affected.
Source: Manifold