CTIPilot
← Back to Daily brief 2026-09-03
NOTABLECVE-2026-72718 +1updatedNATOB1vulnerability

GitSpawn (CVE-2026-72718); a hostile repository's own git config runs arbitrary commands during AI coding agents' routine startup housekeeping, before any trust prompt

Opening a repository received as files, not cloned, can hand an attacker a shell before the agent has asked a single question

Defender actions

  • Before opening any repository received as files rather than cloned (a zip, sync folder, or USB stick), inspect its .git/config for a core.fsmonitor entry or any other setting naming an external program, treat any such entry as a live command, not configuration.
  • Update every AI coding agent in use to its patched build now (Claude Code ≥ 2.1.196 for the core.fsmonitor sink, Goose ≥ 1.44.0, OpenAI Codex and Cursor current); Qwen Code, Grok Build, Hermes Agent, and Claude Code's separate claude ultrareview sink remain unpatched as of 1 September 2026, restrict or avoid running these against repositories of uncertain provenance until fixed.

Analysis

Manifold Security's GitSpawn research starts from an operational fact about how CLI AI coding agents behave: on opening a folder, several gather repository context by running ordinary git commands (git status, git diff) before the agent has received a prompt, shown a workspace-trust dialog, or in some cases completed authentication (Manifold Security, 2026-09-01). Any git command that refreshes the index honours the repository's own .git/config, including core.fsmonitor, a performance hook where git hands the index refresh off to an external helper program named in that config file. A hostile .git/config setting [core] fsmonitor = <arbitrary command> turns the agent's own routine startup housekeeping into unconditional command execution, with no approval prompt and nothing shown on screen (Manifold Security, 2026-09-01). Delivery is narrower than a typical supply-chain vector: cloning, fetching or pulling from a hostile URL does not carry .git/config across, so the repository has to arrive as files with its .git directory already present, a shared zip, a sync folder, a shared drive, or a USB stick, the way colleagues and consultants routinely hand off projects (Manifold Security, 2026-09-01).

Manifold reports eight findings across seven agents, four of which remain unpatched at publication. Confirmed patched: Goose's git diff sink during goose review (CVE-2026-72718, CVSS 4.0 7.0, fixed in 1.44.0), Claude Code's core.fsmonitor sink (fixed in 2.1.196), OpenAI Codex, and Cursor. OpenAI separately disclosed and patched three of its own CVEs for a distinct Codex helper mechanism in the same vulnerability class, crediting three unrelated research groups; only CVE-2026-19592 is named in the cited reporting, describing a helper that runs outside Codex's command sandbox without a user-approval prompt and can read, change or delete the user's files (The Hacker News, 2026-09-02). Confirmed unpatched as of Manifold's 1 September 2026 recheck: Claude Code carries a second, separate sink in claude ultrareview, "not core.fsmonitor ... a different git setting of the same kind, one the review path does not strip," per Manifold, which withholds the specific config key while it remains unfixed; Qwen Code's git status fires at startup, before authentication; Grok Build's payload fires on the first keystroke, with an earlier July report on the same class closed by xAI as "informative"; and Hermes Agent's git status on first message remains unpatched despite six contact attempts across five channels, with VulnCheck assigning CVE-2026-71963 in the vendor's place (Manifold Security, 2026-09-01; The Hacker News, 2026-09-02). Manifold states the underlying pattern is not limited to the named agents and spans both major AI labs and large software companies (heise Security, 2026-09-02).

Mitigation is two-sided: a defender receiving a repository as files should inspect .git/config before opening it in any agent (any entry naming an external program is suspicious) and an agent vendor's own fix is to sanitise the git config on context-gathering calls, e.g. git -c core.fsmonitor=false status (Manifold Security, 2026-09-01). Triage: a git subprocess spawned by an AI coding agent that itself spawns a further, unrelated child process, particularly one launched before the agent has logged any user prompt or shown a trust dialog, is not normal agent startup behaviour and is the observable signature the mechanism supports.

Cited evidence

Open a folder with Claude Code and it runs git status before you type anything. Before the workspace-trust prompt. On some agents, before you have even authenticated.

Delivery is worth being precise about, because git never carries this. Cloning a hostile URL does nothing, and neither does fetch or pull. The repository has to arrive as files with its .git directory already inside, so the vector is anything that moves a directory instead of cloning it: a shared .zip, a shared drive, a sync folder, a USB stick.

Manifold Security 2026-09-01

Updates1

Improvement

CVE-2026-19592's CVSS 3.1 base score of 7.3 (AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H) comes from NVD's own record rather than from any of the articles cited above; The Hacker News states that Goose's 7.0 is the only score its reporting carries, and the two statements are consistent once the score's source is named (NVD record for CVE-2026-19592, retrieved 2026-09-06).

Sources3

Revision history

  1. Published 2026-09-03T0410Z-intel
  2. Improvement 2026-09-06T1308Z-audit

    The sourcing note now attributes CVE-2026-19592's CVSS 7.3 to NVD, the authority that publishes it, resolving an apparent tension with the cited reporting's statement that Goose's score was the only one it carried.

    Changed: sourcing_note body

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.