PulseAugur
实时 08:17:09
Italiano(IT) GitSpawn: come un file .git/config trasforma i tuoi agenti AI in un vettore RCE Una ricerca di Manifold Security mostra come una semplice riga in .git/config po

AI编码工具中的GitSpawn漏洞允许通过Git配置执行代码

Manifold Security的研究人员发现了一个关键漏洞,称为GitSpawn,影响了多个AI编码助手。该漏洞不在于AI模型本身,而在于一个名为`core.fsmonitor`的长期存在的Git功能。此功能旨在提高性能,但可以通过恶意的`.git/config`文件进行利用。当AI代理在打开项目文件夹时自动运行Git命令时,它可能会触发此功能,从而以用户的权限执行任意代码,绕过安全措施和用户确认。 AI

影响 此漏洞凸显了将AI代理与开发工具集成所带来的风险,并强调了在底层基础设施中实施健全安全实践的必要性。

排序理由 在多个AI编码工具中发现安全漏洞,并非新的模型发布或重大行业事件。

在 Mastodon — sigmoid.social 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

AI编码工具中的GitSpawn漏洞允许通过Git配置执行代码

本文如何被排名

Signal score
14 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
在多个AI编码工具中发现安全漏洞,并非新的模型发布或重大行业事件。
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
safety, product
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
Breaking (< 6h)
Fresh story with cross-source coverage still developing. Ranking may shift as more sources report.

完整方法见我们的编辑标准

报道来源 [1]

  1. Mastodon — sigmoid.social TIER_1 Italiano(IT) · [email protected] ·

    GitSpawn:一个.git/config文件如何将您的AI代理变成RCE漏洞 Manifold Security的一项研究表明,.git/config中的单行代码可以

    GitSpawn: come un file .git/config trasforma i tuoi agenti AI in un vettore RCE Una ricerca di Manifold Security mostra come una semplice riga in .git/config possa far eseguire codice arbitrario a Claude Code, Codex, Cursor e altri agenti AI da riga di comando: meccanismo dell'at…