Manifold Security has identified eight critical vulnerabilities affecting seven command-line AI coding agents, including Claude, Codex, and Cursor. The core issue lies within the agents' handling of Git configurations, where malicious repository settings can trigger commands that execute directly on the user's machine without any user consent or sandboxing. Notably, four of these vulnerabilities remain unpatched at the time of reporting, raising significant concerns for developers relying on these AI tools.
For businesses, this revelation underscores the importance of scrutinizing software supply chains and the potential risks posed by integrating AI agents into development workflows. Organizations must enforce stringent security protocols, including reviewing Git configurations and implementing checks to mitigate the risk of executing untrusted code. This situation highlights a larger trend in cybersecurity where AI tools, while beneficial, can inadvertently introduce new vulnerabilities, necessitating a proactive approach to safeguard against emerging threats.
---
*Originally reported by [The Hacker News](https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html)*