Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository’s own Git configuration names a command that the agent runs on the developer’s machine, four of them still unpatched at publication.

The command executes as the user, outside the agent’s sandbox and without an approval prompt, and exploitation requires the repository to arrive

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management

DeepSeek: Reverse Engineering an AI Assistant by Interviewing Itself

DeepSeek: Reverse Engineering an AI Assistant by Interviewing Itself Source: Hacker News

AI can’t be listed as inventor on patent applications, Japan’s top court rules

AI can’t be listed as inventor on patent applications, Japan’s top court rules Source: Hacker News