I have watched teams hand AI coding agents more trust than they give their own junior developers. Claude Code, Codex and Cursor can read your repositories, run commands, modify files and push code, all behind a quick approval prompt. Last week, Manifold Security showed that one of those approvals is imaginary.
The git you did not run
The research, called GitSpawn, covers eight flaws across seven AI coding agents. The mechanism is embarrassingly simple. When an agent opens a project it runs routine git commands such as git status or git diff to gather context. Git reads a performance setting called core.fsmonitor straight out of the repository’s own .git/config file. That setting names a helper program, and git runs it automatically during an index refresh. A malicious repository can therefore ship a command, the agent runs git, and the command executes on your machine with your full user privileges. No prompt. No approval. On some agents, before you have even authenticated.
Who is affected
The affected list reads like a who’s who of AI coding tools: Claude Code, OpenAI Codex, Cursor, Grok Build, Qwen Code, Goose and Hermes Agent. Claude Code alone pulls more than 77 million npm downloads a month. Codex and Cursor have since been patched after the reports were filed as duplicates. Goose fixed its variant in version 1.44.0, earning CVE-2026-72718. Qwen Code, Grok Build, Hermes Agent and a second Claude Code flaw in its ultrareview command were still unpatched when researchers retested on September 1. Hermes Agent’s case is instructive: the vendor never responded to six contact attempts, so VulnCheck assigned CVE-2026-71963 itself.
What an attacker gets
Your SSH keys, the cloud credentials sitting in your environment, the tokens in your shell config, and every repository on your disk. The command runs outside the agent’s sandbox, so the permission model never sees it. This is not a prompt injection that might be refused. It is silent, privileged code execution.
How it reaches you
The delivery vector is the part that should worry every team. A normal git clone is safe, because cloning never transfers another repository’s local .git/config. The poison arrives as files: a zipped folder, a shared drive, a synced directory or a USB stick. That is exactly how consultants hand over projects and how colleagues share work. Your next handoff could be the one carrying the payload.
What to do now
First, treat any repository that arrives as a folder rather than a clone as hostile until proven otherwise. Check its .git/config for core.fsmonitor and any other custom settings before an agent opens it.
Second, update now. Claude Code users should be on version 2.1.196 or later, and Goose users on 1.44.0 or later. If you run Qwen Code, Grok Build or Hermes Agent, assume you are exposed until the vendors ship fixes.
Third, insist that your team clones from trusted remotes. Code that arrives in zips, shared drives or USB sticks should go through a clean clone, not straight into an agent.
Fourth, watch what your agents run in the background. If a tool gathers context by calling git, that context gathering is an attack surface. Disable core.fsmonitor where you can, and pressure vendors to sanitise git configuration during those background calls.
This is the third trust-boundary disclosure this year across overlapping AI coding vendors. The pattern is clear: agents are being given the keys to the kingdom, and the plumbing underneath them was never built for it. Your approval prompts are not the control they appear to be.
Every AI coding agent you trust is only as safe as the repository it opens. GitSpawn proves the sandbox has a back door, and nobody asked for your permission to use it.
Related Reading
Claude Code Now Runs Autonomously by Default. Is Your Codebase Ready?
Hackers Poisoned the AI Water Supply. LiteLLM Shows How Deep the Damage Goes
AI Agents Broke Out of Their Cages This Summer. Enterprises Are Next
The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

