Threat Intelligence

Malicious Git Configs Can Trick AI Coding Assistants Into Running Attacker Commands

The Hacker News · 3 Sept 2026
Key Takeaway Treat any AI coding assistant with the same caution as running unknown code — avoid opening unfamiliar or untrusted repositories with these tools until vendors confirm patches are applied.

Security researchers at Manifold Security have identified eight vulnerabilities across seven widely used command-line AI coding assistants, including tools like Claude, Codex, and Cursor. The flaws stem from how these agents handle a repository's Git configuration file, which can specify a command name for the agent to execute automatically.

The danger is that this command runs directly on the developer's machine as their user account, bypassing the agent's usual sandbox protections and skipping any approval prompt the user would normally see. For the attack to work, a victim needs to obtain and open a malicious repository, such as one shared via a pull request, code sample, or open-source contribution, meaning social engineering plays a key role in real-world exploitation.

At the time of publication, four of the eight flaws had been patched by the affected vendors, while four remained unresolved. This highlights a growing risk area as AI coding tools become embedded in everyday development workflows: attackers are learning to exploit the trust these agents place in project files, not just the code itself.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.