GitSpawn Lets Malicious Repositories Run Code Through AI Coding Agents
Key Takeaways
- Manifold Security disclosed eight GitSpawn findings across seven AI coding agents.
- A malicious repository's Git settings could make an agent run attacker code during routine background commands.
- Claude Code, Codex, Cursor, and Goose shipped fixes; Qwen Code, Grok Build, and Hermes Agent were unpatched at disclosure.
- CVEs were assigned for Codex CLI, Codex Desktop, Goose, and Hermes Agent.
- No exploitation has been reported.
Opening a Folder Became Running a Program
AI coding agents gather context by running ordinary Git commands the moment they open a project. GitSpawn turned that habit into an execution path. As Cyber Press reported, a repository carrying a crafted configuration could make the agent launch attacker code without the developer approving anything.
What We Know
Manifold Security disclosed GitSpawn in early September 2026, with eight findings across Claude Code, OpenAI Codex, Cursor, Block's Goose, Alibaba's Qwen Code, xAI's Grok Build, and Hermes Agent. According to a Cloud Security Alliance research note, Claude Code (version 2.1.196), Cursor, Codex, and Goose (version 1.44.0) were patched, while Qwen Code, Grok Build, Hermes Agent, and a second Claude Code variant remained open at disclosure.
CVE-2026-19592 and CVE-2026-19593 cover Codex CLI and Desktop, CVE-2026-72718 covers Goose, and CVE-2026-71963 covers Hermes Agent. No exploitation has been reported.
What Could Happen
Git's core.fsmonitor setting names a helper program that Git runs automatically when it refreshes its file index. An attacker who controls a repository's local .git/config file can point that setting at any command. When the agent runs git status or git diff for context, Git executes the attacker's command with the developer's privileges.
Standard cloning does not copy .git/config, so the attack relies on repositories shared as folders, archives, cloud-synced directories, or direct handoffs. Those are common in contractor work, bug reports, and code reviews, and many developers would never inspect hidden Git files first.
Why It Matters
GitSpawn is part of a pattern in 2026: agents that act automatically on untrusted input inherit old tooling risks at machine speed. The same repository could compromise many developers who open it with an agent, exposing source code, secrets, and cloud credentials.
Mixed patch status across vendors means risk depends on which agent each developer uses. Security teams need visibility into which coding agents and versions are running, and controls that apply regardless of vendor.
PointGuard AI Perspective
Coding agents should not execute anything their users have not effectively authorized. PointGuard AI Agentic Endpoint Security discovers coding agents on developer machines, tracks versions against known vulnerabilities, and applies policy to the commands and processes agents spawn, so a hidden Git helper can be detected and blocked.
PointGuard AI Security Testing helps teams evaluate how their agent workflows handle untrusted repositories and inputs before attackers do. Trustworthy use of AI coding agents depends on governing what agents execute on the endpoint, not only what code they write.
Incident Scorecard Details
Total AISSI Score: 6.3/10
Criticality: 6, Code execution on developer endpoints can expose source code and credentials. AISSI weighting: 25%
Propagation: 8, Eight findings spanned seven widely used coding agents, and one repository could affect many developers. AISSI weighting: 20%
Exploitability: 5, Researchers confirmed working attacks, but delivery requires sharing a repository outside normal cloning. AISSI weighting: 15%
Supply Chain: 8, The risk comes from third-party agents and untrusted shared repositories. AISSI weighting: 15%
Business Impact: 5, Several agents remained unpatched, though no exploitation or losses were reported. AISSI weighting: 25%
Sources
Third-Party Sources
- Cyber Press: GitSpawn Flaws Let Malicious Repositories Execute Code in Claude Code, Codex, Cursor and Grok
- Cloud Security Alliance: GitSpawn, Malicious Git Configs Hijack AI Coding Agents
