Product
high
threat
Arbitrary Code Execution in AI Coding Agents via Git Configuration
1 rule 1 TTPMultiple AI coding agents are vulnerable to arbitrary code execution due to the automated, unsandboxed execution of commands defined within a repository's local Git configuration, specifically the 'core.fsmonitor' setting.
exploited
goose +8
supply-chain
rce
ai-security
git
1r
1t
critical
advisory
AI Coding Agents Vulnerable to Supply Chain Attacks via Malicious Repositories
2 rules 1 TTPAI coding agents like Claude Code, Gemini CLI, Cursor CLI, and GitHub Copilot Agents can be manipulated to introduce malicious code into software supply chains by accessing attacker-controlled repositories, leading to potential remote code execution and supply chain compromises.
Claude Code +3
supply chain
ai
remote code execution
2r
1t