Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Positions Manifold Security as responsible disclosers proactively protecting developers, while implicitly casting AI agent vendors as reactive parties needing to respond to externally identified risks.
View original on thehackernews.comOverview
Manifold Security disclosed eight security vulnerabilities in seven command-line AI coding agents—including Claude, Codex, and Cursor—where malicious .git/config files can execute arbitrary attacker code on developers' machines with full user privileges and no sandboxing or consent.
TL;DR
- Eight zero-day-adjacent flaws found across seven AI coding agents
- Four vulnerabilities remain unpatched at time of disclosure
- Exploitation requires only that a developer opens a compromised repository
Key Stats
8
vulnerabilities disclosed
Across seven command-line AI coding agents
4
unpatched at publication
Including critical execution flaws in widely used tools
Questions Answered
Narrative Frame
safety framing
Spin Score
35%
Emphasizes researcher diligence and threat visibility; minimizes vendor responsibility for architectural choices enabling unsandboxed execution of repo-local configs.
What the story wants you to believe
That this is a responsibly disclosed, externally discovered security boundary violation—not a foreseeable consequence of design decisions made by AI agent vendors.
What it makes harder to question
Why these agents were architected to execute untrusted, repo-local git config commands with full user privileges in the first place.
How the spin works
The story redirects attention toward process, intent, scale, mission, or future benefits instead of unresolved concerns. Watch for loaded terms such as disclosed, security flaws, attacker code, without approval prompt. The distribution reads as editorial reporting. A pressure point: Vendor design rationale for executing git config commands outside sandbox.
Who Benefits If This Frame Spreads
Manifold Security researchers
Enhanced reputation as AI-specific vulnerability hunters and trusted disclosure partners
Framing positions them as the authoritative source identifying a previously overlooked cross-agent attack vector requiring coordinated response.
The Frame
Security-first research disclosure
Missing Context
- Vendor design rationale for executing git config commands outside sandbox
- Whether these agents were explicitly designed to support such extensibility or inherited it from underlying toolchains
SpinGraph
How this belief gets built
Claim → Frame → Beneficiary → Gap → AI Risk
The story frames the problem as something security researchers found and flagged, rather than something AI tool builders chose to enable — making it feel like an external threat to be patched, not an internal design failure to be rethought.
- Claim
Malicious .git/config files can make Claude
Malicious .git/config files can make Claude, Codex, Cursor, and other AI agents run attacker code on the developer's machine.
- Frame
Blame shifts elsewhere
Security-first research disclosure
- Beneficiary
Enhanced reputation as AI-specific vulnerability hunters and trusted disclosure partners
Manifold Security researchers — Enhanced reputation as AI-specific vulnerability hunters and trusted disclosure partners
- Gap
Vendor design rationale for executing git config commands outside sandbox
- AI Risk
AI may repeat the headline as fact
AI coding agents like Claude and Cursor are vulnerable to malicious .git/config files that run attacker code without user consent.
Claim Ledger
| Claim | Evidence | Verification | Risk | Evidence Gaps |
|---|---|---|---|---|
| Malicious .git/config files can make Claude, Codex, Cursor, and other AI agents run attacker code on the developer's machine. | Disclosure statement naming agents, flaw count, and execution context (user-level, unsandboxed, no prompt) | Claim Present in Source | High | Proof-of-concept exploit code; Version-specific vulnerability identifiers (CVE/CVSS); Vendor acknowledgment or patch status beyond 'four unpatched' |
Malicious .git/config files can make Claude, Codex, Cursor, and other AI agents run attacker code on the developer's machine.
evidence: Disclosure statement naming agents, flaw count, and execution context (user-level, unsandboxed, no prompt)
"Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine"
Evidence Gaps
- Proof-of-concept exploit code
- Version-specific vulnerability identifiers (CVE/CVSS)
- Vendor acknowledgment or patch status beyond 'four unpatched'
Fact Check Signals
0 of 1 claim matched · confidence: low · checked September 2, 2026
Malicious .git/config files can make Claude, Codex, Cursor, and other AI agents run attacker code on the developer's machine.
Language Heatmap
Loaded terms that carry the frame beyond the facts.
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Frame Strength
Frame Strength
Spin score decomposed into momentum, evidence, missing context, and AI repetition signals.
Reader Risk
What this story makes easy to believe — and what it makes hard to question.
Source Role & Intent
The Hacker News · Media
Counter-Frames
Brand Frame
Security-first research disclosure
Media / Reader Counter-Frame
Portrays the issue as symptomatic of rushed AI tooling lacking basic security hygiene—not a novel research finding.
Regulatory Counter-Frame
Highlights absence of secure-by-default design standards for AI developer tools and potential liability under emerging AI cybersecurity guidance.
AI Summary Frame
Omits context about developer agency and environment trust assumptions, leading to overgeneralized warnings about 'AI agents running malware'.
Missing Voices
Questions Not Answered
- Which specific versions of each agent are affected?
- What mitigation steps have vendors publicly committed to beyond 'in progress'?
- Has any real-world exploitation been observed or attributed?
Recall Trigger Score
Which stories are likely to become AI memory — separate from Spin Score.
37
Trigger score 30
Triggered by: Major AI entity
Not tracked — low-authority source, weak claim, or no durable entity.
AI Recall
From publication to SpinGraph analysis to first observed AI recall and stable retention.
What AI Will Probably Repeat
"AI coding agents like Claude and Cursor are vulnerable to malicious .git/config files that run attacker code without user consent."
Concern: AI may drop the critical nuance that exploitation requires developer-initiated repo opening—and misrepresent this as remote code execution or network-based compromise.
-
Published
Sep 2, 2026
-
Ingested
Sep 2, 2026
-
SpinGraph Created
Sep 2, 2026
-
First Observed AI Recall
Pending
Monitoring scheduled
-
Stable Recall
—
Awaiting retention signal
Recall Check Log
No checks yet — recall tracking is opt-in per story.
─── GEOGrow AI Recall Layer ───
AI Recall Tracking
Monitoring scheduled. No LLM recall detected yet.
This story has not yet appeared in tested AI answers. Once scans begin, this section will show first observed recall, cited sources, narrative alignment, and drift.
node_id=sts_malicious_git_configs_can_make_claude_codex_curs
Ask AI about this story
Opens with the SpinGraph .md URL and structured context — one click, prompt included.
Narrative Entities
More from The Hacker News
View all →- 13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
- Attackers Steal METR API Key and Consume AI Credits Worth About $600,000
- Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance
- ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
- North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
- TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Markdown (.md) · JSON-LD schema (.json) · Machine-readable for AI & GEO