CTIPilot

Block Goose

product · product:block-goose

Coverage timeline
1
first 2026-09-03 → last 2026-09-03
Peak priority
notable
1 notable
Sources cited
3
3 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
8
see Co-occurring entities below
ATT&CK techniques
2
pinned v19.2 · see below

Hunting pivots

Releases covered
Block Goose
ATT&CK techniques

ATT&CK techniques

2 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Execution TA0002

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-09-03/gitspawn-ai-coding-agent-git-config-hijack · ATT&CK page ↗

T1204.002User Execution: Malicious File×1

An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.

Evidence: 2026-09-03/gitspawn-ai-coding-agent-git-config-hijack · ATT&CK page ↗

Story timeline

  1. 2026-09-03GitSpawn (CVE-2026-72718); a hostile repository's own git config runs arbitrary commands during AI coding agents' routine startup housekeeping, before any trust prompt
    trending-vulnerabilitiesOpening a repository received as files, not cloned, can hand an attacker a shell before the agent has asked a single question

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • heise.de1 (33%)
  • manifold.security1 (33%)
  • thehackernews.com1 (33%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Block Goose (1)

2026-09-03 · view entry permalink →

NOTABLECVE-2026-72718 +1updatedNATOB1

GitSpawn (CVE-2026-72718); a hostile repository's own git config runs arbitrary commands during AI coding agents' routine startup housekeeping, before any trust prompt

Manifold Security's GitSpawn research starts from an operational fact about how CLI AI coding agents behave: on opening a folder, several gather repository context by running ordinary git commands (git status, git diff) before the agent has received a prompt, shown a workspace-trust dialog, or in some cases completed authentication (Manifold Security, 2026-09-01). Any git command that refreshes the index honours the repository's own .git/config, including core.fsmonitor, a performance hook where git hands the index refresh off to an external helper program named in that config file. A hostile .git/config setting [core] fsmonitor = <arbitrary command> turns the agent's own routine startup housekeeping into unconditional command execution, with no approval prompt and nothing shown on screen (Manifold Security, 2026-09-01). Delivery is narrower than a typical supply-chain vector: cloning, fetching or pulling from a hostile URL does not carry .git/config across, so the repository has to arrive as files with its .git directory already present, a shared zip, a sync folder, a shared drive, or a USB stick, the way colleagues and consultants routinely hand off projects (Manifold Security, 2026-09-01).

Manifold reports eight findings across seven agents, four of which remain unpatched at publication. Confirmed patched: Goose's git diff sink during goose review (CVE-2026-72718, CVSS 4.0 7.0, fixed in 1.44.0), Claude Code's core.fsmonitor sink (fixed in 2.1.196), OpenAI Codex, and Cursor. OpenAI separately disclosed and patched three of its own CVEs for a distinct Codex helper mechanism in the same vulnerability class, crediting three unrelated research groups; only CVE-2026-19592 is named in the cited reporting, describing a helper that runs outside Codex's command sandbox without a user-approval prompt and can read, change or delete the user's files (The Hacker News, 2026-09-02). Confirmed unpatched as of Manifold's 1 September 2026 recheck: Claude Code carries a second, separate sink in claude ultrareview, "not core.fsmonitor ... a different git setting of the same kind, one the review path does not strip," per Manifold, which withholds the specific config key while it remains unfixed; Qwen Code's git status fires at startup, before authentication; Grok Build's payload fires on the first keystroke, with an earlier July report on the same class closed by xAI as "informative"; and Hermes Agent's git status on first message remains unpatched despite six contact attempts across five channels, with VulnCheck assigning CVE-2026-71963 in the vendor's place (Manifold Security, 2026-09-01; The Hacker News, 2026-09-02). Manifold states the underlying pattern is not limited to the named agents and spans both major AI labs and large software companies (heise Security, 2026-09-02).

Mitigation is two-sided: a defender receiving a repository as files should inspect .git/config before opening it in any agent (any entry naming an external program is suspicious) and an agent vendor's own fix is to sanitise the git config on context-gathering calls, e.g. git -c core.fsmonitor=false status (Manifold Security, 2026-09-01). Triage: a git subprocess spawned by an AI coding agent that itself spawns a further, unrelated child process, particularly one launched before the agent has logged any user prompt or shown a trust dialog, is not normal agent startup behaviour and is the observable signature the mechanism supports.

Open a folder with Claude Code and it runs git status before you type anything. Before the workspace-trust prompt. On some agents, before you have even authenticated.

Delivery is worth being precise about, because git never carries this. Cloning a hostile URL does nothing, and neither does fetch or pull. The repository has to arrive as files with its .git directory already inside, so the vector is anything that moves a directory instead of cloning it: a shared .zip, a shared drive, a sync folder, a USB stick.

Manifold Security 2026-09-01
Improvementrun 2026-09-06T1308Z-auditsourcing_notebody

CVE-2026-19592's CVSS 3.1 base score of 7.3 (AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H) comes from NVD's own record rather than from any of the articles cited above; The Hacker News states that Goose's 7.0 is the only score its reporting carries, and the two statements are consistent once the score's source is named (NVD record for CVE-2026-19592, retrieved 2026-09-06).

vulnerability03 Sep 05:13Zmulti-sourceOpen finding ↗