Source · DiggingBeagle record

GitSpawn: A Single Flaw Lets Untrusted Repos Run Code in Claude Code, Codex, Cursor, and Grok

Manifold Security's primary disclosure of eight Git-configuration findings across seven AI coding agents, including the core.fsmonitor execution path, delivery preconditions and patch status at publication.

Published
Sep 1, 2026
Accessed
Sep 19, 2026
Publisher
Manifold Security
Source type
research_disclosure
Version
GitSpawn disclosure, 2026-09-01

Each support, contradiction or context label applies to a cited Claim, not to a whole Case.

Source record

Four of the eight findings are still live.

Read the original source ↗

Claim-level citations (5)

Cite this record

DiggingBeagle. “GitSpawn: A Single Flaw Lets Untrusted Repos Run Code in Claude Code, Codex, Cursor, and Grok.” Published Sep 1, 2026 · Accessed Sep 19, 2026. https://diggingbeagle.com/sources/gitspawn-a-single-flaw-lets-untrusted-repos-run-code-in-claude-code-codex-cursor/

Citation guidance

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.