Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository’s own Git configuration names a command that the agent runs on the developer’s machine, four of them still unpatched at publication.

The command executes as the user, outside the agent’s sandbox and without an approval prompt, and exploitation requires the repository to arrive

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root

Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and

We never use AI. For anything

We never use AI. For anything Source: Hacker News