AIthehackernews.com·8d ago

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

Submitted by @

Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive

ORIGINAL REPORTING
The Hacker News
Published 8d ago ago · info@thehackernews.com (The Hacker News)
Read full story at The Hacker News

Original reporting by The Hacker News · info@thehackernews.com (The Hacker News). GridIndex is an aggregation and intelligence layer — full credit to the original publisher.

CONTINUE READING

This page summarizes and tracks coverage of this developing story.

Read full story at The Hacker News
0 views 0 upvotes 0 comments 0 shares

Discussion · 0

Sign in to join the discussion.