GitSpawn: The Booby-Trapped Repo That Runs Code in Claude Code, Codex and Cursor

I have watched teams hand AI coding agents more trust than they give their own junior developers. Claude Code, Codex and Cursor can read your repositories, run commands, modify files and push code, all behind a quick approval prompt. Last week, Manifold Security showed that one of those approvals is imaginary.

The git you did not run

The research, called GitSpawn, covers eight flaws across seven AI coding agents. The mechanism is embarrassingly simple. When an agent opens a project it runs routine git commands such as git status or git diff to gather context. Git reads a performance setting called core.fsmonitor straight out of the repository’s own .git/config file. That setting names a helper program, and git runs it automatically during an index refresh. A malicious repository can therefore ship a command, the agent runs git, and the command executes on your machine with your full user privileges. No prompt. No approval. On some agents, before you have even authenticated.

Who is affected

The affected list reads like a who’s who of AI coding tools: Claude Code, OpenAI Codex, Cursor, Grok Build, Qwen Code, Goose and Hermes Agent. Claude Code alone pulls more than 77 million npm downloads a month. Codex and Cursor have since been patched after the reports were filed as duplicates. Goose fixed its variant in version 1.44.0, earning CVE-2026-72718. Qwen Code, Grok Build, Hermes Agent and a second Claude Code flaw in its ultrareview command were still unpatched when researchers retested on September 1. Hermes Agent’s case is instructive: the vendor never responded to six contact attempts, so VulnCheck assigned CVE-2026-71963 itself.

What an attacker gets

Your SSH keys, the cloud credentials sitting in your environment, the tokens in your shell config, and every repository on your disk. The command runs outside the agent’s sandbox, so the permission model never sees it. This is not a prompt injection that might be refused. It is silent, privileged code execution.

How it reaches you

The delivery vector is the part that should worry every team. A normal git clone is safe, because cloning never transfers another repository’s local .git/config. The poison arrives as files: a zipped folder, a shared drive, a synced directory or a USB stick. That is exactly how consultants hand over projects and how colleagues share work. Your next handoff could be the one carrying the payload.

What to do now

First, treat any repository that arrives as a folder rather than a clone as hostile until proven otherwise. Check its .git/config for core.fsmonitor and any other custom settings before an agent opens it.

Second, update now. Claude Code users should be on version 2.1.196 or later, and Goose users on 1.44.0 or later. If you run Qwen Code, Grok Build or Hermes Agent, assume you are exposed until the vendors ship fixes.

Third, insist that your team clones from trusted remotes. Code that arrives in zips, shared drives or USB sticks should go through a clean clone, not straight into an agent.

Fourth, watch what your agents run in the background. If a tool gathers context by calling git, that context gathering is an attack surface. Disable core.fsmonitor where you can, and pressure vendors to sanitise git configuration during those background calls.

This is the third trust-boundary disclosure this year across overlapping AI coding vendors. The pattern is clear: agents are being given the keys to the kingdom, and the plumbing underneath them was never built for it. Your approval prompts are not the control they appear to be.

Every AI coding agent you trust is only as safe as the repository it opens. GitSpawn proves the sandbox has a back door, and nobody asked for your permission to use it.

Related Reading

Claude Code Now Runs Autonomously by Default. Is Your Codebase Ready?

Hackers Poisoned the AI Water Supply. LiteLLM Shows How Deep the Damage Goes

AI Agents Broke Out of Their Cages This Summer. Enterprises Are Next

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

Subscribe

Related articles

Zuckerberg and Chan’s Biohub Pours $1.8 Billion Into AI That Simulates Human Cells

Mark Zuckerberg and Priscilla Chan's Biohub has expanded its Virtual Biology Initiative to $1.8 billion, backed by the US government, Google DeepMind, and Meta. The goal is AI that can simulate human cells and transform drug discovery.

The Free AI Tool That Just Hacked Seven Banks: The Skill Floor Has Disappeared

An open-source AI penetration testing tool called ARTEX was used to breach seven South Korean financial institutions and expose 68,000 customer records. The scary part is anyone can use it.

OpenAI Drops 722 Math Papers in One Go, Claims Major Proof Breakthroughs

OpenAI has released 722 mathematics papers from an unreleased model, including a quasi-Riemann hypothesis proof. The drop marks a turning point for AI-driven discovery.

Someone Built a Fake AI Ad Empire to Steal Your Login. And It Worked.

A human-operated phishing platform is impersonating ChatGPT, Gemini, Claude, Perplexity and Meta Muse with fake advertising portals that steal credentials and bypass MFA. Island researchers found hundreds of victims and the campaign is still running.

Reflection AI’s Beam Is the West’s Latest Answer to China’s Open-Weight Dominance

After two years and $25 billion in valuation, Reflection AI has finally released its first public model. Beam is an open-weight entry aimed at coding and agents, but the gap with Chinese rivals remains wider than many expected.
Philip Hall
Philip Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.