CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

September 2, 2026

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code Swati KhandelwalSep 02, 2026Vulnerability / AI Coding Agent Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive as files with its .git directory intact, which a shared archive, a shared drive, a sync folder, or a USB stick preserves, whereas an ordinary clone does not. Fixes have shipped for goose, Claude Code, and Cursor,…

CVEs: CVE-2026-19592, CVE-2026-72718, CVE-2021-43891, CVE-2022-24346, CVE-2026-55607, CVE-2026-71963