# Git configuration flaws expose several AI coding agents to local command execution

_Wednesday, September 2, 2026 at 10:06 AM EDT · Security, AI · Latest · Tier 1 — Major_

Manifold Security disclosed eight flaws across seven command-line AI coding agents that can cause a repository's Git configuration to name a command executed on a developer's machine.

The article says exploitation requires a received repository with its .git directory intact, rather than an ordinary clone. It reports fixes for goose, Claude Code and Cursor; Hermes Agent, Qwen Code, Grok Build and a second Claude Code path remained unpatched at publication. OpenAI published three CVEs covering the class in Codex, according to the article.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html)

---
Canonical: https://techandbusiness.org/newswire/X3FvZfdEIfP-t3PCb7OXCw
Retrieved: 2026-09-02T23:56:57.657Z
Publisher: Tech & Business (techandbusiness.org)
