The latest in AI, every dayAI News
← AI News

September 13, 2026 · The Hacker News

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

My take: When you open a repository with Claude Code, Codex, or Cursor, those tools inspect the repo's state before you do anything. GitSpawn abuses that trust: a malicious .git/config file can execute arbitrary code on your machine before you're prompted for permission, and in some agents, before you've even authenticated. Seven of the most widely used AI coding tools today are vulnerable to this class of attack.

What matters here is not only the attack itself, but what it reveals about how these tools are designed. As AI agents become a standard part of development workflows, the security perimeter shifts. It's no longer just about what code you write, it's about which repositories you open and with which tool. Four of the eight documented vulnerabilities were still unpatched as of September 1.

Patched versions already exist for Claude Code, Cursor, and Goose. The fix is technically straightforward, but it requires updating. Does your team have a process to keep the AI tools your engineers use up to date?

Read at the source: The Hacker News ↗

Want to use these tools? See the unbiased reviews or back to the news.