According to Manifold Security, AI coding agents including Claude Code, OpenAI's Codex, and Cursor are vulnerable to code execution via malicious Git repositories through a vulnerability called GitSpawn. The agents run git status before workspace-trust prompts or user authentication to gather context, allowing repository content to execute arbitrary commands with developer credentials and SSH keys. OpenAI's Codex and Cursor have since been patched; the flaw affects context-gathering mechanisms across multiple agent products.
Topics #
Sources #
- Press Read article
Go deeper #
This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.