TL;DR
- A vulnerability class called GitSpawn lets a poisoned Git repository run code on a developer’s machine the moment an AI coding agent opens it — before any prompt or approval.
- Manifold Security disclosed 8 findings across 7 agents on September 2, 2026. Four remained unpatched as of their September 1 retest: Claude Code (/ultrareview path), Qwen Code, Grok Build, and Hermes Agent.
- Standard
git cloneis safe. Risk arrives via zip archives, shared drives, or any channel that transfers the.gitdirectory intact.
Who should care: Engineering teams using Claude Code, Cursor, Codex, Goose, Qwen Code, Grok Build, or Hermes Agent — and any team that accepts repositories via file transfer rather than a fresh remote clone.
Verdict: Act now — run one line to disable fsmonitor globally, check your agent versions, and audit how repos reach developer machines.
How a Booby-Trapped Repository Runs Code in Your Agent
Git has a configuration setting called core.fsmonitor. When set, Git runs the named program each time it refreshes its index — which happens whenever you call git status or git diff. AI coding agents call both automatically at startup to gather project context.
A malicious repository embeds an attacker-controlled command in .git/config, pointing core.fsmonitor at arbitrary code. When the agent opens the repository and runs its context-gathering step, Git executes that command as a native subprocess, with the developer’s full user privileges, completely outside the agent’s tool-call permission layer. No approval prompt appears. According to Manifold Security’s disclosure, execution precedes the workspace-trust dialog in several of the tested agents.
Standard git clone, fetch, and pull do not transfer .git/config from the remote, so the attack does not arise from cloning a repository. It arises when a repository arrives as files with its .git directory intact: a zip archive, shared drive, USB stick, synced folder, or Slack attachment.
Claude Code’s /ultrareview command has a second, distinct variant. It uses a different Git configuration key — which Manifold has not named publicly because the flaw remains unpatched — and the payload executes before the review begins and before the workspace-trust prompt is shown. The core.fsmonitor path was patched in Claude Code v2.1.196; the ultrareview path was reported on July 15, 2026 and was still present at v2.1.252 on September 1, Manifold’s last published retest. October changelogs through v2.1.292 include security fixes for other ultrareview issues but do not mention the GitSpawn variant.
Patch Status: Eight Findings, Four Still Open
Manifold tracked eight findings across seven agents. The table below reflects their September 1, 2026 retest — the most recent published data — and the CVE record where one exists.
| Agent | Reported | Status (Sep 1, 2026) | Fixed version | CVE |
|---|---|---|---|---|
| Claude Code (core.fsmonitor) | Jun 26, 2026 | ✅ Patched | v2.1.196 | — |
| Claude Code (/ultrareview) | Jul 15, 2026 | ❌ Unpatched at v2.1.252 | Not yet | — |
| Cursor | Jul 8, 2026 | ✅ Patched | Current release | — |
| OpenAI Codex CLI | Jul 20, 2026 | ✅ Patched | v0.131.0 | CVE-2026-19592 |
| OpenAI Codex Desktop | Jul 20, 2026 | ✅ Patched | Per CVE record | CVE-2026-19593 |
| Goose | Jul 13, 2026 | ✅ Patched | v1.44.0 | CVE-2026-72718 (CVSS 7.0) |
| Qwen Code (Alibaba) | Jul 7, 2026 | ❌ Unpatched at v0.22.3 | Not yet | — |
| Grok Build (xAI) | Jul 14, 2026 | ❌ Unpatched at v1.0.13 | Not yet | — |
| Hermes Agent | Jul 20, 2026 | ❌ Unpatched at v0.21.0 | Not yet | CVE-2026-71963 |
Sources: Manifold Security (primary disclosure); CSA Research Note; Cybersecurity News.
Five of the eight reports were closed as duplicates of findings other researchers had filed independently. That means GitSpawn was known in some form before Manifold published — and several vendors still shipped no fix. Claude Code had over 77 million npm downloads per month as of August 27, 2026, according to the npm API cited in the Manifold write-up. The seven affected agents together have close to half a million GitHub stars.
What a Successful Attack Reaches
Because the subprocess runs with the developer’s full OS privileges, the attacker’s code can access SSH keys, cloud credentials (AWS, GCP, Azure), shell history, and every other repository present on the same machine. The CSA Research Note states this explicitly, calling the accessible surface “SSH keys, cloud credentials, shell history, and every other repository present on the same disk.”
For teams running agents in CI with credentials for production infrastructure — a common configuration for automated code review and agentic PR workflows — the blast radius extends to those systems. This is not a theoretical risk: the attack does not require user interaction beyond a developer receiving and opening a repository file.
GitSpawn is not an isolated incident. A vortx.ch analysis of deployed agentic AI found that 81% of agents are deployed outside formal security controls, meaning most teams have no systematic way to know which agent version is running where. The same month as GitSpawn’s disclosure, Wiz published GhostApproval, a symlink-based confirmation bypass affecting six agents (July 8, 2026). A pattern is forming: agents execute Git and filesystem operations before trust boundaries are checked.
What to Do on Monday
Five steps, in order of effort and impact:
- Apply the blanket one-liner. Run
git config --global core.fsmonitor falseon every developer machine and CI runner today. This disables fsmonitor processing for all repositories. Manifold Security recommends it as an immediate interim measure. It has no functional side effect in typical workflows. - Check Claude Code and Goose versions. Run
claude --version. Version 2.1.196 or later has the first GitSpawn fix; no published version yet addresses the/ultrareviewvariant. For Goose, confirm you are on v1.44.0 or later (CVE-2026-72718). For OpenAI Codex CLI, confirm v0.131.0 or later (CVE-2026-19592). For Cursor, update to the current release. - Audit how repositories reach developer machines. If code arrives as a zip, sync tool, or shared drive (Dropbox, Google Drive, OneDrive), treat it as untrusted and inspect
.git/configbefore opening it in any agent. Rungit config --get core.fsmonitorinside the repository root. A non-empty result means a command is set — review it carefully before proceeding. - Hold off on
/ultrareviewfor untrusted repos. Until Anthropic publishes an advisory for the second Claude Code finding, restrict the/ultrareviewcommand to repositories you have cloned fresh from a trusted remote. Do not run it on repositories received as file transfers. - Add GitSpawn remediation status to your vendor reviews. The CSA Research Note recommends requiring vendors to describe their configuration-handling posture as part of procurement and security reviews. For the EU AI Act’s high-risk and general-purpose AI system categories, documented agent security reviews are already expected under Article 9 and 11 obligations — see our earlier analysis of the agentic AI gap in the EU AI Act.
Further Reading
- GitSpawn: A Single Flaw Lets Untrusted Repos Run Code in Claude Code, Codex, Cursor, and Grok — Manifold Security’s full technical disclosure with patch status table and reproduction steps.
- CSA Research Note: AI Coding Agent Git Config RCE — independent analysis with AICM v1.1 control mapping and vendor mitigation recommendations.
- GitSpawn Flaws Let Malicious Repositories Execute Code in Claude Code, Codex, Cursor, and Grok — clear summary of the full scope, useful for briefing a CISO or security team.
Your turn: Has your team already restricted which commands agents can run on repositories received as file transfers, or is it still first-clone-then-trust? Reply to our newsletter or send us a note — we feature the best answers in the Friday Scorecard.
How this article was made: AI researched and wrote this article under the Christian persona, using the sources linked above, and it was published automatically without a human edit. Editorial guidelines are set by Adi. Spotted an error? Tell us and we will correct it.

