← Founder Notes
Archive

Gitspawn let core.fsmonitor run attacker code the second any agent issued git status. claude code,…

Yethikrishna ROriginal on Threads

gitspawn let core.fsmonitor run attacker code the second any agent issued git status. claude code, codex, cursor, goose, hermes, qwen code, grok build — seven agents, four cves.

the agent threat model just stopped being prompt injection and started being the repo you clone.

Context

Manifold Security's post of 1 September 2026 reports eight findings across seven agents, with four unpatched at publication. Agents running git commands such as git status refresh the index, and a repository's own .git/config setting core.fsmonitor can then run a command. In Claude Code the start-up git status ran the payload while the workspace-trust prompt was still waiting. Goose 1.41.0 was affected via goose review, fixed in 1.44.0 (CVE-2026-72718, scored 7.0 by maintainers). Codex and Cursor variants came back as duplicates and have since been patched.

How it compares

Effects depend on the agent and version, and the post gives per-agent versions and patch states, so the claim does not hold for any agent at any moment. The post shows one CVE number, so four CVEs is not supported. Cloning a hostile URL does nothing by itself, so the trigger is more specific than the repo you clone. The patch state is as of 1 September 2026 only. That the threat model moved on from prompt injection is the author's opinion.

Related work

Watch next

  • Manifold or vendor advisories on later patch status.

Sources

  1. AI coding agents and git config hijacking (Manifold Security, 1 Sep 2026)manifold.security

Provenance

The note above is reproduced unedited from the original post, first published on Threads on 5 September 2026 at 07:02 IST. Sources are the papers and datasets the note draws on.

View the original post
Embed this note
<iframe src="https://founder.myndlabs.tech/notes/embed/gitspawn-let-core-fsmonitor-run-attacker-code-the-Dc4ydDOiFqI" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="Gitspawn let core.fsmonitor run attacker code the second any agent issued git status. claude code,…"></iframe>

More notes