GitHub Copilot CLI before version 1.0.43 is vulnerable to arbitrary command execution when it performs Git operations in a project directory containing an attacker-controlled nested bare Git repository. Git's automatic bare-repository discovery can cause the nested repository's configuration to be used during directory traversal. Executable Git configuration options, including core.fsmonitor and other external-command settings, may then invoke attacker-specified shell commands during otherwise routine Git operations such as status, diff, or repository resolution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a real proof-of-concept exploit for a malicious-repository attack against Claude Code's git-structure permission guard. It demonstrates a guard bypass where a repository plants files that cause git to execute attacker-controlled commands via core.fsmonitor when the agent runs a git command from a crafted subdirectory. Repository structure has two main parts. container/ builds an isolated Docker bench with two Claude Code versions installed side by side: 2.1.162 (vulnerable) and 2.1.163 (patched). Scripts there automate image creation, login/auth persistence, environment reset, and interactive testing. malicious-repo/ builds the actual malicious repository from a benign JavaScript monorepo template. The template is a legitimate Node workspace package with tests and a build script, used as camouflage. The exploit logic is in malicious-repo/build.sh. It copies the benign template, then adds four attack elements: (1) a symlink packages/web/current -> ., used for path laundering; (2) staged payload files under packages/web/.buildcache/, including a git config with core.fsmonitor and a pre-commit hook; (3) a malicious packages/web/CLAUDE.md that instructs the agent to run a single bootstrap command; and (4) user steering so the agent starts inside packages/web, where the planted git directory takes precedence. The bootstrap command creates HEAD/objects/refs/hooks through the symlinked current/ path, copies in config and hook files, marks the hook executable, writes HEAD, and finally runs git status --short. Because the vulnerable guard checks lexical paths, it misses current/HEAD and related paths even though they resolve to git structure files in the working directory. Primary capability: arbitrary shell command execution inside Claude Code's sandbox, triggered indirectly by git via core.fsmonitor. The included payload is intentionally inert: it appends timestamps and the current working directory to /tmp/.bench-marker and returns false. A secondary execution path exists through hooks/pre-commit if a commit is performed. No network beacons, exfiltration, or destructive actions are present. The exploit is operational rather than weaponized: it includes a working payload and full reproduction environment, but the payload is hardcoded and benign. It is not merely a detector; verify.sh actually executes the malicious bootstrap command in a fresh clone and confirms that git triggers the planted fsmonitor. The README and RUNBOOK clearly document expected behavior differences between vulnerable and patched Claude Code versions, including the permission prompt that should appear in 2.1.163.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.