Source · DiggingBeagle record
GitSpawn: A Single Flaw Lets Untrusted Repos Run Code in Claude Code, Codex, Cursor, and Grok
Manifold Security's primary disclosure of eight Git-configuration findings across seven AI coding agents, including the core.fsmonitor execution path, delivery preconditions and patch status at publication.
- Published
- Sep 1, 2026
- Accessed
- Sep 19, 2026
- Publisher
- Manifold Security
- Source type
- research_disclosure
- Version
- GitSpawn disclosure, 2026-09-01
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
Four of the eight findings are still live.
Claim-level citations (5)
- supportsGitSpawn let received repositories execute code before AI coding-agent trust gates: The core repository-delivery path requires the victim to receive a directory with its .git metadata intact; Manifold notes that ordinary clone, fetch and pull do not copy a remote repository's local .git/config.
Delivery discussion explaining archives, shared drives, sync folders and USB copies versus git clone
- supportsGitSpawn let received repositories execute code before AI coding-agent trust gates: In the documented core.fsmonitor path, an agent's automatic Git context-gathering command could cause Git to execute a helper command stored in the repository's own .git/config, outside the agent sandbox and without a tool-approval prompt.
Sections 'The git you didn't run' and core.fsmonitor explanation
- supportsGitSpawn let received repositories execute code before AI coding-agent trust gates: The researchers documented product paths where attacker code executed before the user's normal workspace-trust, model-interaction or approval boundary had taken effect.
TL;DR and per-agent case studies describing execution timing
- supportsGitSpawn let received repositories execute code before AI coding-agent trust gates: Manifold Security reported eight related findings across seven AI coding agents, including Claude Code, OpenAI Codex, Cursor, Goose, Qwen Code, Grok Build and Hermes Agent.
TL;DR and 'Eight findings across seven agents' section
- supportsGitSpawn let received repositories execute code before AI coding-agent trust gates: Manifold's September 1 publication reported eight findings across seven agents; four findings were fixed and four were still unpatched at that publication snapshot.
TL;DR and timeline table: eight findings across seven agents, status at publication
Cite this record
DiggingBeagle. “GitSpawn: A Single Flaw Lets Untrusted Repos Run Code in Claude Code, Codex, Cursor, and Grok.” Published Sep 1, 2026 · Accessed Sep 19, 2026. https://diggingbeagle.com/sources/gitspawn-a-single-flaw-lets-untrusted-repos-run-code-in-claude-code-codex-cursor/
Citation guidance