GitSpawn Lets Malicious Repositories Run Code Through AI Coding Agents

Key Takeaways

  • Manifold Security disclosed eight GitSpawn findings across seven AI coding agents.
  • A malicious repository's Git settings could make an agent run attacker code during routine background commands.
  • Claude Code, Codex, Cursor, and Goose shipped fixes; Qwen Code, Grok Build, and Hermes Agent were unpatched at disclosure.
  • CVEs were assigned for Codex CLI, Codex Desktop, Goose, and Hermes Agent.
  • No exploitation has been reported.

Opening a Folder Became Running a Program

AI coding agents gather context by running ordinary Git commands the moment they open a project. GitSpawn turned that habit into an execution path. As Cyber Press reported, a repository carrying a crafted configuration could make the agent launch attacker code without the developer approving anything.

What We Know

Manifold Security disclosed GitSpawn in early September 2026, with eight findings across Claude Code, OpenAI Codex, Cursor, Block's Goose, Alibaba's Qwen Code, xAI's Grok Build, and Hermes Agent. According to a Cloud Security Alliance research note, Claude Code (version 2.1.196), Cursor, Codex, and Goose (version 1.44.0) were patched, while Qwen Code, Grok Build, Hermes Agent, and a second Claude Code variant remained open at disclosure.

CVE-2026-19592 and CVE-2026-19593 cover Codex CLI and Desktop, CVE-2026-72718 covers Goose, and CVE-2026-71963 covers Hermes Agent. No exploitation has been reported.

What Could Happen

Git's core.fsmonitor setting names a helper program that Git runs automatically when it refreshes its file index. An attacker who controls a repository's local .git/config file can point that setting at any command. When the agent runs git status or git diff for context, Git executes the attacker's command with the developer's privileges.

Standard cloning does not copy .git/config, so the attack relies on repositories shared as folders, archives, cloud-synced directories, or direct handoffs. Those are common in contractor work, bug reports, and code reviews, and many developers would never inspect hidden Git files first.

Why It Matters

GitSpawn is part of a pattern in 2026: agents that act automatically on untrusted input inherit old tooling risks at machine speed. The same repository could compromise many developers who open it with an agent, exposing source code, secrets, and cloud credentials.

Mixed patch status across vendors means risk depends on which agent each developer uses. Security teams need visibility into which coding agents and versions are running, and controls that apply regardless of vendor.

PointGuard AI Perspective

Coding agents should not execute anything their users have not effectively authorized. PointGuard AI Agentic Endpoint Security discovers coding agents on developer machines, tracks versions against known vulnerabilities, and applies policy to the commands and processes agents spawn, so a hidden Git helper can be detected and blocked.

PointGuard AI Security Testing helps teams evaluate how their agent workflows handle untrusted repositories and inputs before attackers do. Trustworthy use of AI coding agents depends on governing what agents execute on the endpoint, not only what code they write.

Incident Scorecard Details

Total AISSI Score: 6.3/10

Criticality: 6, Code execution on developer endpoints can expose source code and credentials. AISSI weighting: 25%

Propagation: 8, Eight findings spanned seven widely used coding agents, and one repository could affect many developers. AISSI weighting: 20%

Exploitability: 5, Researchers confirmed working attacks, but delivery requires sharing a repository outside normal cloning. AISSI weighting: 15%

Supply Chain: 8, The risk comes from third-party agents and untrusted shared repositories. AISSI weighting: 15%

Business Impact: 5, Several agents remained unpatched, though no exploitation or losses were reported. AISSI weighting: 25%

Sources

Third-Party Sources

PointGuard AI Sources

AI Security Severity Index (AISSI)

0/10

Threat Level

Criticality

6

Propagation

8

Exploitability

5

Supply Chain

8

Business Impact

5

Scoring Methodology

Category

Description

weight

Criticality

Importance and sensitivity of theaffected assets and data.

25%

PROPAGATION

How easily can the issue escalate or spread to other resources.

20%

EXPLOITABILITY

Is the threat actively being exploited or just lab demonstrated.

15%

SUPPLY CHAIN

Did the threat originate with orwas amplified by third-partyvendors.

15%

BUSINESS IMPACT

Operational, financial, andreputational consequences.

25%

Watch Incident Video

Learn More

Use Cases

Glossary

Products

Blogs

Subscribe for updates:

Subscribe

Ready to get started?

Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.