Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: git-config (1 article)Clear

Malicious repository settings can make AI coding agents run attacker commands

Researchers at Manifold Security disclosed a class of flaws across several command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs automatically on the developer's machine. The command executes outside the agent's sandbox, with the user's privileges, and without any approval prompt, often before the agent even contacts the model. Simply reviewing or opening a malicious project can run attacker code. It triggers when a repository arrives as files with its hidden Git directory intact, such as through a shared drive, archive, or USB stick, rather than a normal clone. Several tools shipped fixes, but some remained vulnerable at disclosure.

Check
Update command-line AI coding agents to patched versions, treat opening or reviewing an untrusted repository in an agentic tool as running its code, and prefer plain clones over copied repositories.
Affected
Developers using command-line AI coding agents who open untrusted repositories delivered as files with their Git directory intact; repository settings can execute attacker commands outside the sandbox, without approval.
Fix
Keep agent tools updated, run them against untrusted code in isolated environments, restrict what the agent can reach, avoid opening repositories from shared drives or archives without inspection, and watch startup commands.