Manifold Security disclosed GitSpawn, a vulnerability class in which AI coding agents automatically invoke Git commands such as git status or git diff while opening a repository, causing attacker-controlled core.fsmonitor commands in the repository’s .git/config to execute. The commands run with the developer’s local user privileges, outside the agent sandbox and before trust or approval controls may apply, enabling code execution without a build step or explicit user action. The technique extends a previously demonstrated abuse of Git’s legitimate FSMonitor feature, which can also trigger when IDEs such as VS Code or Cursor inspect a malicious repository.
Affected products reportedly included goose, OpenAI Codex, Claude Code, Hermes Agent, Qwen Code, Grok Build, and Cursor. Patches were available for goose, Codex, Cursor, and one Claude Code path, while Hermes Agent, Qwen Code, Grok Build, and another Claude Code issue remained unresolved or unpatched. The primary exposure is repositories delivered locally with a preserved .git directory, including ZIP archives; ordinary cloning, pulling, and fetching do not transfer the malicious local configuration. Organizations should treat locally received repositories as untrusted, audit for suspicious core.fsmonitor settings, disable FSMonitor by default where feasible, and update affected agent tools.

Track how attackers are adapting to this technology.
11 events from the most recent confirmed update back to the earliest known activity.
Manifold tested Claude Code version 2.1.252 and found that a separate command-execution path through claude ultrareview remained active, despite a fix for the core.fsmonitor path.
CVE-2026-71963 affects Hermes Agent versions 0.18.2 through 0.21.0, where a malicious repository can set core.fsmonitor and cause command execution when a user opens it and sends a message. The issue was fixed in commit f6234d00c5d59450adea1d7edd30ad3859375c79; exploitation could expose the user's environment, including configured provider API keys.
Manifold reported confirmed GitSpawn exposure in Hermes Agent, Qwen Code, and Grok Build, with fixes pending or unresolved. Qwen Code could execute before authentication, while Grok Build could trigger execution on the first keystroke; xAI reportedly closed the Grok report as a duplicate of an earlier informative report.
Cursor remediated a related repository-supplied setup-command issue in its CLI that could execute before the workspace-trust prompt and outside the product sandbox.
Anthropic fixed the core.fsmonitor GitSpawn path affecting Claude Code 2.1.193 by version 2.1.196. A separate claude ultrareview path remained unresolved in Manifold's later testing.
OpenAI fixed the affected Codex CLI releases in version 0.131.0 and released fixed Codex Desktop versions for macOS and Windows. OpenAI published three CVEs for the vulnerability class, including CVE-2026-19592, which could permit code to read, modify, or delete user files and access account-available resources.
Goose versions before 1.44.0 were affected by the repository-controlled fsmonitor execution issue, and version 1.44.0 fixed it. GitHub assigned CVE-2026-72718, with a CVSS 4.0 base score of 7.0.
Manifold Security disclosed eight GitSpawn flaws across seven command-line AI coding agents. Received repositories retaining a malicious .git/config could cause background Git operations such as status or diff to execute attacker-controlled commands as the developer, outside agent sandboxes and without approval.
Anthropic's June advisory for CVE-2026-55607 identified execution of Git fsmonitor during Claude Code worktree operations.
Sonar reported the same Git execution sink in April and noted earlier workspace-trust-dialog bypasses affecting Visual Studio Code and JetBrains IDEs. The report identified repository-triggered Git execution as a risk before the later GitSpawn disclosure.
A proof of concept showed that a malicious repository can set core.fsmonitor in .git/config to an attacker-controlled script, which can execute when IDEs such as VSCode or Cursor automatically run Git commands on opening the folder. The demonstration worked on macOS and was described as adaptable to Windows and Linux; it abuses legitimate Git behavior rather than a patched vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcecvefeed.io
Open sourcethehackernews.com
Open sourceheise.de
Open sourcemanifold.security
Open sourcecobalt.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.