GitSpawn Flaws Let Malicious Repositories Execute Code in Claude Code, Codex, Cursor, and Grok

A newly disclosed class of vulnerabilities, dubbed GitSpawn, allows a booby-trapped repository to silently execute code on a developer’s machine the moment it is opened with an AI coding agent, no prompt typed, no approval clicked, and in some cases before the user has even authenticated. Security researchers at Manifold Security found the flaw while […]

This article has been indexed from Cyber Security News

Read the original article: