Researchers at Manifold Security have identified a critical vulnerability, dubbed GitSpawn, affecting multiple AI coding assistants. The flaw lies not in the AI models themselves, but in a long-standing Git feature called `core.fsmonitor`. This feature, designed for performance, can be exploited through a malicious `.git/config` file. When an AI agent automatically runs Git commands upon opening a project folder, it can trigger this feature, leading to arbitrary code execution with the user's privileges, bypassing security measures and user confirmation. AI
IMPACT This vulnerability highlights the risks of integrating AI agents with development tools and underscores the need for robust security practices in underlying infrastructure.
RANK_REASON Security vulnerability discovered in multiple AI coding tools, not a new model release or major industry event.
Read on Mastodon — sigmoid.social →
- Claude Code
- Cursor+
- Git
- GitHub
- GitSpawn
- Goose
- Grok Build
- Hermes Agent
- Manifold Security
- OpenAI Codex CLI
- Qwen Code
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →