CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5556

As cited

Copy frozen at (site build).

ai security

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

Manifold Security disclosed eight security flaws across seven command-line artificial intelligence (AI) coding agents in which a repository's Git configuration can name a command that the agent executes on the developer's machine without a sandbox or approval prompt. Four of the affected agents remained unpatched at the time of disclosure. Exploitation requires the repository to be present on the developer's system.

Why it matters: Developers using Claude, Codex, Cursor, and other AI coding agents face remote code execution (RCE) risk when cloning or working with malicious repositories, as the agents run attacker-controlled commands with user privileges.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary