Manifold Security discloses GitSpawn vulnerability enabling arbitrary code execution in AI coding agents Manifold Security disclosed a vulnerability named GitSpawn that enables arbitrary code execution in AI coding agents, including Claude Code, OpenAI's Codex, and Cursor, via malicious Git repositories. The flaw allows repository content to execute commands with developer credentials and SSH keys because agents run `git status` before workspace-trust prompts or user authentication. OpenAI's Codex and Cursor have been patched, but the issue affects context-gathering mechanisms across multiple agent products. Manifold Security discloses GitSpawn vulnerability enabling arbitrary code execution in AI coding agents According to Manifold Security, AI coding agents including Claude Code, OpenAI's Codex, and Cursor are vulnerable to code execution via malicious Git repositories through a vulnerability called GitSpawn. The agents run git status before workspace-trust prompts or user authentication to gather context, allowing repository content to execute arbitrary commands with developer credentials and SSH keys. OpenAI's Codex and Cursor have since been patched; the flaw affects context-gathering mechanisms across multiple agent products. Topics Sources - Press Read article https://www.manifold.security/blog/ai-coding-agents-git-hijack Go deeper This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.