TGViewer
Linux Linux @sysadminoff · 2.13K subscribers
Post #19822 59
GitSpawn lets poisoned repositories run code through AI coding agents

A repository’s own `.git/config` can still trigger attacker-controlled code through Claude Code, Codex, Cursor, goose, and other AI coding agents before trust prompts, authentication, model calls, or tool approvals occur. Manifold Security’s GitSpawn research found eight flaws across seven agents; fixes are available for several tools, but Hermes Agent, Qwen Code, Grok Build, and a second Claude Code path remained vulnerable during September testing.
Source

👉@sysadminoff

https://4sysops.com/archives/gitspawn-lets-poisoned-repositories-run-code-through-ai-coding-agents/
More from @sysadminoff
  1. Oct 4, 2026📰 The Netherlands Picked NixOS. France Was Already Using It France’s digital agency has b…
  2. Oct 4, 2026Госорганы Нидерландов и Франции внедряют решения на базе NixOS Министерство внутренних дел…
  3. Oct 4, 2026Выпуск мобильной платформы /e/OS 4.3 Представлен выпуск мобильной платформы /e/OS 4.3, сфо…
  4. Oct 3, 2026📰 Linux Mint replaced Ubuntu as the best first distro, and Ubuntu's own choices explain w…
  5. Oct 3, 2026📰 Archinstall 4.5 Arch Linux Installer Adds AArch64 Support for GRUB and Limine Archinsta…
  6. Oct 3, 2026📰 AMD Boosting AI/LLM Performance For Radeon iGPUs As Much As 18~23% With Linux 7.4 If yo…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →