Security Researchers Reveal Git Config Exploits That Let AI Coding Tools Execute Malicious Commands
Manifold Security has uncovered a series of vulnerabilities affecting a range of command-line AI coding assistants, including Claude, Codex, Cursor and several others. The flaw stems from the way these agents interpret a repository's .git configuration file, allowing a maliciously crafted command to be run automatically on a developer's machine when the AI tool processes the repository.
The researchers identified eight distinct issues across seven different agents. In each case, the AI program reads the "core.command" (or similar) entry in a .git config and, assuming it is benign, executes the specified command without prompting the user. Because the command originates from the repository itself, an attacker who can push a crafted commit can trigger arbitrary code execution on any machine that runs the affected AI tool.
Four of the eight vulnerabilities remain unpatched at the time of disclosure, meaning that users of the affected tools continue to be exposed. The unpatched agents include popular open‑source and commercial offerings that developers rely on for code generation, debugging and documentation tasks. Manifold Security has provided proof‑of‑concept demonstrations showing how a simple "git pull" followed by an AI‑assisted code suggestion can lead to the execution of a reverse shell or the installation of additional malware.
These findings highlight a broader security challenge in the emerging space of AI‑driven development tools. Many of the agents were designed to streamline workflows by automatically cloning repositories, reading configuration files, and running helper scripts. However, the convenience of automatic execution has outpaced rigorous input validation, creating an attack surface that mirrors classic supply‑chain threats seen in traditional software builds.
Industry observers note that the issue is not limited to the specific agents named in the report. Any command‑line AI assistant that parses Git configuration values without sanitization could be vulnerable. The problem is compounded by the fact that developers often run these tools with elevated privileges, making the potential impact severe. Security best practices now recommend reviewing .git config entries before invoking AI helpers, especially when working with external or untrusted code bases.
Manifold Security has coordinated disclosure with the vendors involved, and patches for the remaining vulnerabilities are expected in upcoming releases. In the interim, the researchers advise users to disable automatic execution of Git‑defined commands in their AI tools, restrict the tools' permissions, and audit repository configurations before use. As AI coding assistants become more entrenched in software development pipelines, this incident serves as a reminder that security hygiene must evolve alongside functionality.
Comments (0)
Be the first to comment.
Join the discussion