The record
Written from the 1 report below. Nothing here is unsourced.
- Eight security flaws in seven AI coding agents let a repository's Git configuration file run attacker commands on a developer's machine, per findings by Manifold Security.
- The command runs outside the agent's sandbox and without any approval prompt, so it can read, change, or delete a user's files with full user privileges.
- Fixes have shipped for goose, Claude Code, and Codex, but Hermes Agent, Qwen Code, Grok Build, and a second Claude Code path were still unpatched when retested on September 1.
- Exploitation requires the repository to arrive with its .git directory intact, which shared archives, sync folders, or USB sticks can preserve but an ordinary clone does not.
- The flaws matter because an agent can execute malicious code before the user approves a trust dialog, authenticates, or even types a single keystroke.
What to watch next
Coverage1
1 report
English national1
All filed from IndiaSingle origin
Named Thailand · United States · Alibaba · Anthropic · Claude Code · Codex · Cursor · goose · Grok Build · Hermes Agent · Nous Research · OpenAI · Qwen Code · xAI
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
