Malicious Git configs enable code execution in agents
🔒 Manifold Security disclosed eight vulnerabilities across seven CLI AI coding agents where a repository's .git config can name commands the agent runs locally as the user, bypassing sandboxes and prompts. Some vendors have released fixes (goose, Claude Code core.fsmonitor path, Cursor), while Hermes Agent, Qwen Code, Grok Build, and a second Claude Code path remained unpatched at Manifold's retest on September 1. OpenAI published related CVEs for Codex the same day.
