Gitspawn let core.fsmonitor run attacker code the second any agent issued git status. claude code,…
gitspawn let core.fsmonitor run attacker code the second any agent issued git status. claude code, codex, cursor, goose, hermes, qwen code, grok build — seven agents, four cves.
the agent threat model just stopped being prompt injection and started being the repo you clone.
Context
Manifold Security's post of 1 September 2026 reports eight findings across seven agents, with four unpatched at publication. Agents running git commands such as git status refresh the index, and a repository's own .git/config setting core.fsmonitor can then run a command. In Claude Code the start-up git status ran the payload while the workspace-trust prompt was still waiting. Goose 1.41.0 was affected via goose review, fixed in 1.44.0 (CVE-2026-72718, scored 7.0 by maintainers). Codex and Cursor variants came back as duplicates and have since been patched.
Effects depend on the agent and version, and the post gives per-agent versions and patch states, so the claim does not hold for any agent at any moment. The post shows one CVE number, so four CVEs is not supported. Cloning a hostile URL does nothing by itself, so the trigger is more specific than the repo you clone. The patch state is as of 1 September 2026 only. That the threat model moved on from prompt injection is the author's opinion.
Related work
- CSA research note on GitSpawn (Cloud Security Alliance) ↗Secondary note, seen as a snippet only.
Watch next
- Manifold or vendor advisories on later patch status.
Sources
Provenance
The note above is reproduced unedited from the original post, first published on Threads on 5 September 2026 at 07:02 IST. Sources are the papers and datasets the note draws on.
View the original post ↗Embed this note
More notes
The air is now being asked to keep its own ledger
the air is now being asked to keep its own ledger: ecmwf’s aifs compo becomes the first ai model to forecast atmospheric composition globally every three hours, cleanair simulates 365 days of pm2.5 over china in ten seconds, and a unified framework maps six pollutants at one kilometer across the whole country. the air now files its own composition report.
read the note →The current is now being asked to draw its own map
the current is now being asked to draw its own map: china’s langya 2.0 predicts six ocean phenomena including internal waves and mesoscale eddies, a deep net called wenhai resolves eddies globally with air sea flux formulas built in, and scripps infers surface currents from the way temperature patterns deform in satellite images. the ocean now files its own circulation report.
read the note →The soil is now being asked to report its own carbon
the soil is now being asked to report its own carbon: a nix color sensor paired with generative data augmentation predicts soil organic carbon without a lab, random forest drives 74 percent of soil health mapping studies, and sentinel 2 tracks five year carbon change across france and italy from 922 samples. the dirt now files its own carbon account.
read the note →