Kryptovaluta-ticker:
sysadmin fra Cyber Security News

GitSpawn Flaws Let Malicious Repositories Execute Code in Claude Code, Codex, Cursor, and Grok

Guru Baran
Sep 2, 2026 at 16:29
66 Visninger
0 Kommentarer
GitSpawn Flaws Let Malicious Repositories Execute Code in Claude Code, Codex, Cursor, and Grok

A newly disclosed class of vulnerabilities, dubbed GitSpawn, allows a booby-trapped repository to silently execute code on a developer’s machine the moment it is opened with an AI coding agent, no prompt typed, no approval clicked, and in some cases before the user has even authenticated. Security researchers at Manifold Security found the flaw while investigating what CLI-based coding agents actually do on startup, as detailed in the technical disclosure published by Manifold Security. Nearly every agent they examined gathers project context by quietly running git commands like git status or git diff in the background. That behavior is unremarkable on its own, but each of these commands triggers git to refresh its internal...

Les hele artikkelen hos kilden.

Delta i diskusjonen — kommenter, stem og del lenker.

Registrer
Var dette nyttig?
Del:

Kommentarer (0)

Vennligst logg inn eller registrer deg for å delta i diskusjonen

Ingen kommentarer ennå. Bli den første til å kommentere!