{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/xai/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["goose (\u003c 1.44.0)","Codex CLI (0.102.0 - 0.130.0)","Codex Desktop for macOS (260202.0859 - 26.513.31313)","Codex Desktop for Windows (26.304.38 - 26.513.40821)","Claude Code (2.1.193, 2.1.252)","Hermes Agent (0.18.2, 0.21.0)","Qwen Code (0.19.6, 0.22.3)","Grok Build (0.2.93, 1.0.13)","Cursor CLI"],"_cs_severities":["high"],"_cs_tags":["supply-chain","rce","ai-security","git"],"_cs_type":"threat","_cs_vendors":["OpenAI","Anthropic","Nous Research","Alibaba","xAI","Cursor"],"content_html":"\u003cp\u003eManifold Security has disclosed eight security vulnerabilities affecting seven command-line AI coding agents, collectively dubbed GitSpawn. The flaw stems from the agents' behavior of reading and executing commands defined in a repository's local Git configuration file ('.git/config') during routine repository indexing operations like 'git status' or 'git diff'. Specifically, the 'core.fsmonitor' Git configuration parameter, which is intended to identify changed files, can be abused by an attacker to specify an arbitrary command that the host agent executes. This command runs with the privileges of the developer, bypasses the agent's sandbox, and executes before any user-approval or workspace-trust prompt. Impacted agents include goose, Claude Code, Cursor, Codex, Hermes Agent, Qwen Code, and Grok Build. While some vendors have released patches, others remain vulnerable. Exploitation requires the victim to open a malicious repository containing a manipulated '.git' directory, typically provided via shared archives, sync folders, or removable media.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker creates a malicious Git repository containing a crafted '.git/config' file.\u003c/li\u003e\n\u003cli\u003eThe '.git/config' file is modified to set 'core.fsmonitor' to an arbitrary malicious command or script path.\u003c/li\u003e\n\u003cli\u003eThe repository is delivered to a developer via a shared folder, USB drive, or archive that preserves the hidden '.git' directory.\u003c/li\u003e\n\u003cli\u003eThe developer opens the repository directory using an affected AI coding agent.\u003c/li\u003e\n\u003cli\u003eThe AI agent initiates a background Git operation (such as 'git status' or 'git diff') to index the workspace.\u003c/li\u003e\n\u003cli\u003eGit reads the malicious 'core.fsmonitor' configuration and automatically executes the defined command.\u003c/li\u003e\n\u003cli\u003eThe command executes on the developer's machine with user-level privileges, outside the agent's sandbox.\u003c/li\u003e\n\u003cli\u003eFinal objective is achieved, such as file exfiltration, unauthorized file modification, or further payload delivery.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthenticated attackers to achieve full code execution on developer machines, potentially leading to the theft of source code, credentials, or other sensitive files accessible to the user. While no widespread in-the-wild exploitation has been confirmed as of September 2026, the potential for supply chain attacks against software development organizations is significant. Multiple agents remain unpatched as of the disclosure, and the issue affects major platforms including Windows, macOS, and Linux.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately audit development environments for the listed vulnerable AI coding agent versions and apply patches where available (e.g., upgrade goose to 1.44.0+).\u003c/li\u003e\n\u003cli\u003eGlobally disable the 'core.fsmonitor' feature in Git configuration for untrusted repositories by running 'git config --global core.fsmonitor false'.\u003c/li\u003e\n\u003cli\u003eInspect '.git/config' files for suspicious 'core.fsmonitor', 'core.hooksPath', or 'attr.tree' entries before opening repositories with AI-integrated tools.\u003c/li\u003e\n\u003cli\u003eDeploy detection rules to identify execution of Git sub-processes initiated by AI agent binaries that contain suspicious command-line arguments.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T14:20:59Z","date_published":"2026-09-02T14:20:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-gitspawn-ai-agent-rce/","summary":"Multiple AI coding agents are vulnerable to arbitrary code execution due to the automated, unsandboxed execution of commands defined within a repository's local Git configuration, specifically the 'core.fsmonitor' setting.","title":"Arbitrary Code Execution in AI Coding Agents via Git Configuration","url":"https://feed.craftedsignal.io/briefs/2026-09-gitspawn-ai-agent-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - XAI","version":"https://jsonfeed.org/version/1.1"}