New "GitSpawn" Vulnerability Lets AI Code Assistants Run Malicious Commands
Security researchers have identified a novel class of flaw, dubbed "GitSpawn," that affects several AI-powered coding assistants. The weakness stems from the way these tools automatically run Git commands to scan a developer's repository, a process that can be hijacked to execute arbitrary code on the host system.
The issue was uncovered by the team at Manifold Security, who demonstrated that popular agents such as Claude Code, OpenAI's Codex, Cursor, and Grok are vulnerable. By supplying a crafted repository, an attacker can trigger the assistant to run malicious Git operations, potentially leading to the execution of unwanted scripts, data exfiltration, or further system compromise.
AI coding assistants rely on real‑time analysis of a project's source tree to provide context‑aware suggestions. To gather this information, many implementations invoke commands like git clone or git fetch without sufficient sandboxing or validation. The researchers say the automated nature of these calls creates an attack surface that traditional security reviews often overlook.
Manifold Security warned that the flaw could be exploited in environments where developers trust AI agents with privileged access, such as local development machines or CI/CD pipelines. Because the malicious payload can be embedded in a seemingly innocuous Git repository, the attack may bypass conventional code reviews and anti‑malware tools.
Following the disclosure, the affected vendors have been notified and are reportedly working on patches that will isolate Git operations, enforce stricter input validation, and limit the permissions granted to AI agents. In the meantime, experts advise developers to treat AI assistants as untrusted code, run them in isolated containers, and avoid granting them write access to critical directories until the fixes are deployed.
The discovery highlights a broader challenge as AI tools become more integrated into software development workflows. Security professionals stress the need for rigorous threat modeling of AI components, especially those that interact directly with version‑control systems, to prevent similar vulnerabilities from emerging in the future.
Comments (0)
Be the first to comment.
Join the discussion