GitSpawn Flaws Let Malicious Repositories Execute Code in Claude Code, Codex, Cursor, and Grok
ID: 941892aa-3652-5af3-aa89-c41f0cc99e34
STIX ID: report--941892aa-3652-5af3-aa89-c41f0cc99e34
Feed Name: cybersecurityNews.com
Researchers disclosed "GitSpawn," a class of vulnerabilities where malicious repositories carrying a .git directory can execute arbitrary local commands when AI coding agents run background git operations (e.g., git status), leveraging config keys like core.fsmonitor; multiple popular agents were shown vulnerable, some fixes and CVEs have been issued while other issues remain unpatched—users should inspect .git/config and vendors should sanitize git config during context gathering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
