Manifold Security disclosed eight flaws across seven command-line AI coding agents where repository-controlled Git settings could trigger code execution on a developer’s machine, with four issues still unpatched at publication. OpenAI also issued three CVEs for the same attack class in Codex, while affected tools and versions included goose, Claude Code, Codex, Hermes Agent, Qwen Code, and Grok Build. #GitSpawn #ClaudeCode #Codex #goose #HermesAgent #QwenCode #GrokBuild
Keypoints
- Repository-supplied Git settings can run commands on the user’s machine.
- Exploitation works when a repo arrives with its .git directory intact.
- Goose, Claude Code, and Cursor received fixes for some paths.
- Hermes Agent, Qwen Code, and Grok Build were still affected at retest.
- OpenAI published three CVEs for the same issue in Codex.
Read More: https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html