HackerFeeds

CyberSecurity News

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

The Hacker News
· September 2, 2026

AI summary

Researchers at Manifold Security have identified eight security vulnerabilities in seven command-line AI coding agents. These flaws allow a repository's Git configuration to specify a command that the agent will execute on the developer's machine. The command runs outside of the agent's sandbox and without prompting for approval, executing with the user's privileges. Four of the identified vulnerabilities remain unpatched. Exploitation of these vulnerabilities requires the repository to be accessed by the target. The affected agents include Claude, Codex, and Cursor, among others.

Read the full article at The Hacker Newsthehackernews.com/2026/09/malicious-git-configs-can-make-claude.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.