Back to all news
Security

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

The Hacker News·September 2, 2026·1 min read
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

Manifold Security disclosed eight flaws in seven AI coding agents, including Claude, Codex, and Cursor, where malicious .git configs can execute attacker commands on the developer's machine. Four remain unpatched. The command runs outside the sandbox without approval prompts, requiring only a malicious repository.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store