<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code]]></title><description><![CDATA[<p dir="auto">Manifold Security has disclosed eight security flaws across seven command-line AI coding agents, where a repository’s own Git configuration can trick the tool into executing an attacker-controlled command on the developer’s machine. The attack relies on malicious <code>.git</code> config files, which can name a command that the agent unknowingly runs outside its sandbox and without an approval prompt.</p>
<p dir="auto">Four of the eight flaws remain unpatched at the time of publication. The affected agents include popular tools such as <strong>Claude</strong>, <strong>Codex</strong>, and <strong>Cursor</strong>, among others. The command executes with the privileges of the logged-in user, meaning a successful exploit could lead to credential theft, data exfiltration, or full local compromise.</p>
<p dir="auto">Exploitation requires the repository to arrive on the target machine—via a cloned project, a pull request, or a compromised dependency—after which the embedded Git configuration triggers the agent into running the malicious command. The issue highlights a broader risk in AI-assisted development: the trust placed in repository metadata and the assumption that sandboxing is enforced consistently across agent implementations.</p>
<ul>
<li>Attack surface: malicious <code>.git</code> config files within a repository.</li>
<li>Impact: command execution as the current user, bypassing sandbox and approval prompts.</li>
<li>Status: four of the eight vulnerabilities are still unpatched.</li>
</ul>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Are your development teams vetting repositories before letting AI agents open them, or is that trust still assumed by default?</p>
]]></description><link>https://xploitlk.com/topic/198/malicious-.git-configs-can-make-claude-codex-cursor-and-other-ai-agents-run-attacker-code</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 12:37:25 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/198.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 03 Sep 2026 06:30:23 GMT</pubDate><ttl>60</ttl></channel></rss>