GitSpawn Flaw Let Malicious Repos Run Code When Opened in AI Coding Tools
Manifold Security researchers discovered a vulnerability class called GitSpawn affecting seven popular AI coding agents, including Claude Code, Codex, Cursor, and Grok Build. The flaw exploited Git's legitimate core.fsmonitor configuration option, which can point to an external executable program. When developers simply opened a project folder, the coding tool would run background Git commands like git status, inadvertently triggering attacker-controlled code without any user approval prompt. Eight related issues were identified across the affected tools, with exploitation requiring no prompt injection or sandbox escape — just opening a repository was enough. The findings highlight a broader security concern: modern development environments have quietly blurred the line between browsing a codebase and executing it.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in