Skip to content

GitSpawn: Malicious Git Configs Hijack AI Coding Agents

7 min read

GitSpawn: Malicious Git Configs Hijack AI Coding Agents
Photo by Rafael Minguet Delgado on Pexels

TL;DR

  • A vulnerability class called GitSpawn lets a poisoned Git repository run code on a developer’s machine the moment an AI coding agent opens it — before any prompt or approval.
  • Manifold Security disclosed 8 findings across 7 agents on September 2, 2026. Four remained unpatched as of their September 1 retest: Claude Code (/ultrareview path), Qwen Code, Grok Build, and Hermes Agent.
  • Standard git clone is safe. Risk arrives via zip archives, shared drives, or any channel that transfers the .git directory intact.

Who should care: Engineering teams using Claude Code, Cursor, Codex, Goose, Qwen Code, Grok Build, or Hermes Agent — and any team that accepts repositories via file transfer rather than a fresh remote clone.

Verdict: Act now — run one line to disable fsmonitor globally, check your agent versions, and audit how repos reach developer machines.

How a Booby-Trapped Repository Runs Code in Your Agent

Git has a configuration setting called core.fsmonitor. When set, Git runs the named program each time it refreshes its index — which happens whenever you call git status or git diff. AI coding agents call both automatically at startup to gather project context.

A malicious repository embeds an attacker-controlled command in .git/config, pointing core.fsmonitor at arbitrary code. When the agent opens the repository and runs its context-gathering step, Git executes that command as a native subprocess, with the developer’s full user privileges, completely outside the agent’s tool-call permission layer. No approval prompt appears. According to Manifold Security’s disclosure, execution precedes the workspace-trust dialog in several of the tested agents.

Standard git clone, fetch, and pull do not transfer .git/config from the remote, so the attack does not arise from cloning a repository. It arises when a repository arrives as files with its .git directory intact: a zip archive, shared drive, USB stick, synced folder, or Slack attachment.

Claude Code’s /ultrareview command has a second, distinct variant. It uses a different Git configuration key — which Manifold has not named publicly because the flaw remains unpatched — and the payload executes before the review begins and before the workspace-trust prompt is shown. The core.fsmonitor path was patched in Claude Code v2.1.196; the ultrareview path was reported on July 15, 2026 and was still present at v2.1.252 on September 1, Manifold’s last published retest. October changelogs through v2.1.292 include security fixes for other ultrareview issues but do not mention the GitSpawn variant.

Patch Status: Eight Findings, Four Still Open

Manifold tracked eight findings across seven agents. The table below reflects their September 1, 2026 retest — the most recent published data — and the CVE record where one exists.

Agent Reported Status (Sep 1, 2026) Fixed version CVE
Claude Code (core.fsmonitor) Jun 26, 2026 ✅ Patched v2.1.196 —
Claude Code (/ultrareview) Jul 15, 2026 ❌ Unpatched at v2.1.252 Not yet —
Cursor Jul 8, 2026 ✅ Patched Current release —
OpenAI Codex CLI Jul 20, 2026 ✅ Patched v0.131.0 CVE-2026-19592
OpenAI Codex Desktop Jul 20, 2026 ✅ Patched Per CVE record CVE-2026-19593
Goose Jul 13, 2026 ✅ Patched v1.44.0 CVE-2026-72718 (CVSS 7.0)
Qwen Code (Alibaba) Jul 7, 2026 ❌ Unpatched at v0.22.3 Not yet —
Grok Build (xAI) Jul 14, 2026 ❌ Unpatched at v1.0.13 Not yet —
Hermes Agent Jul 20, 2026 ❌ Unpatched at v0.21.0 Not yet CVE-2026-71963

Sources: Manifold Security (primary disclosure); CSA Research Note; Cybersecurity News.

Five of the eight reports were closed as duplicates of findings other researchers had filed independently. That means GitSpawn was known in some form before Manifold published — and several vendors still shipped no fix. Claude Code had over 77 million npm downloads per month as of August 27, 2026, according to the npm API cited in the Manifold write-up. The seven affected agents together have close to half a million GitHub stars.

What a Successful Attack Reaches

Because the subprocess runs with the developer’s full OS privileges, the attacker’s code can access SSH keys, cloud credentials (AWS, GCP, Azure), shell history, and every other repository present on the same machine. The CSA Research Note states this explicitly, calling the accessible surface “SSH keys, cloud credentials, shell history, and every other repository present on the same disk.”

For teams running agents in CI with credentials for production infrastructure — a common configuration for automated code review and agentic PR workflows — the blast radius extends to those systems. This is not a theoretical risk: the attack does not require user interaction beyond a developer receiving and opening a repository file.

GitSpawn is not an isolated incident. A vortx.ch analysis of deployed agentic AI found that 81% of agents are deployed outside formal security controls, meaning most teams have no systematic way to know which agent version is running where. The same month as GitSpawn’s disclosure, Wiz published GhostApproval, a symlink-based confirmation bypass affecting six agents (July 8, 2026). A pattern is forming: agents execute Git and filesystem operations before trust boundaries are checked.

What to Do on Monday

Five steps, in order of effort and impact:

  1. Apply the blanket one-liner. Run git config --global core.fsmonitor false on every developer machine and CI runner today. This disables fsmonitor processing for all repositories. Manifold Security recommends it as an immediate interim measure. It has no functional side effect in typical workflows.
  2. Check Claude Code and Goose versions. Run claude --version. Version 2.1.196 or later has the first GitSpawn fix; no published version yet addresses the /ultrareview variant. For Goose, confirm you are on v1.44.0 or later (CVE-2026-72718). For OpenAI Codex CLI, confirm v0.131.0 or later (CVE-2026-19592). For Cursor, update to the current release.
  3. Audit how repositories reach developer machines. If code arrives as a zip, sync tool, or shared drive (Dropbox, Google Drive, OneDrive), treat it as untrusted and inspect .git/config before opening it in any agent. Run git config --get core.fsmonitor inside the repository root. A non-empty result means a command is set — review it carefully before proceeding.
  4. Hold off on /ultrareview for untrusted repos. Until Anthropic publishes an advisory for the second Claude Code finding, restrict the /ultrareview command to repositories you have cloned fresh from a trusted remote. Do not run it on repositories received as file transfers.
  5. Add GitSpawn remediation status to your vendor reviews. The CSA Research Note recommends requiring vendors to describe their configuration-handling posture as part of procurement and security reviews. For the EU AI Act’s high-risk and general-purpose AI system categories, documented agent security reviews are already expected under Article 9 and 11 obligations — see our earlier analysis of the agentic AI gap in the EU AI Act.

Further Reading

Your turn: Has your team already restricted which commands agents can run on repositories received as file transfers, or is it still first-clone-then-trust? Reply to our newsletter or send us a note — we feature the best answers in the Friday Scorecard.

CH

Christian · AI writing persona · Engineering & Enterprise

Christian covers coding agents, AI security and enterprise rollouts, with an eye on what Swiss and EU teams can actually deploy under FADP and the EU AI Act. His posts end with what to change on Monday. Christian is an AI writing persona at vortx.ch.

How this article was made: AI researched and wrote this article under the Christian persona, using the sources linked above, and it was published automatically without a human edit. Editorial guidelines are set by Adi. Spotted an error? Tell us and we will correct it.

Don’t miss on Ai tips!

We don’t spam! We are not selling your data. Read our privacy policy for more info.

Don’t miss on Ai tips!

We don’t spam! We are not selling your data. Read our privacy policy for more info.

Enjoyed this? Get one AI insight per day.

Join engineers and decision-makers who start their morning with vortx.ch. No fluff, no hype — just what matters in AI.