GitSpawn is a class of vulnerabilities that lets a booby-trapped code repository run commands on a developer’s machine the moment it is opened in an AI coding agent. No prompt is typed and no approval is clicked, and in some cases it fires before the user has even signed in. Researchers at Manifold Security disclosed it on September 2, 2026, and confirmed it in Claude Code, Goose, Hermes Agent, Qwen Code and Grok Build, with variants affecting Cursor and OpenAI’s Codex. Four of the eight tracked issues were still unpatched at disclosure.
How does opening a folder run code?
Almost every coding agent gathers context when it starts by quietly running git commands such as git status or git diff. Those commands make git refresh its internal index. Git has a documented performance setting, core.fsmonitor, that names a helper program to run on every index refresh, and it reads that setting from the repository’s own .git/config file.
So a malicious repository can put any command it likes in that setting. When the agent runs its routine context check, the command executes with the full privileges of the logged-in user. It runs outside the agent’s sandbox and never appears in the permission prompts, because from the agent’s point of view it only ran git status.
Can it reach me through a normal git clone?
No, and that is the main limit on the attack. Clone, fetch and pull never transmit a repository’s .git/config, so a project pulled from GitHub the normal way is not affected. The poisoned repo has to arrive as raw files with its .git folder intact: a zip file, a shared drive, a synced folder or a USB stick. That is exactly how contractors, consultants and colleagues routinely hand projects over, which is what makes it realistic.
Which tools are affected, and what is patched?
- Claude Code: affected, with four flaws tracked. One, in the
ultrareviewcommand, abuses a different git configuration key and was deliberately left unnamed by the researchers. Claude Code is installed more than 77 million times a month on npm. - Goose: fixed, assigned CVE-2026-72718.
- Hermes Agent: assigned CVE-2026-71963 after the vendor did not respond to six contact attempts.
- Cursor and Codex: both patched after reports, each flagged as a duplicate of findings other researchers had filed independently.
- Qwen Code and Grok Build: confirmed vulnerable at disclosure.
Patch status may have moved since September 2, so check each vendor’s changelog rather than relying on this list.
What should developers do now?
If you receive a project as files rather than through a clone, open .git/config in a plain text editor before pointing any AI agent at the folder, and look for fsmonitor or any other entry that names a program. If in doubt, delete the .git folder and re-clone from the real remote. Keep your agents updated. For vendors, the fix the researchers recommend is simple: explicitly disable core.fsmonitor on every background git call.
GitSpawn fits the pattern of agent supply-chain risk we have been tracking, alongside slopsquatting fake packages and agents leaking screenshots to public GitHub. In each case the agent does something ordinary, and the danger sits in what that ordinary action quietly triggers. It is also a reminder that sandboxing the agent does not help when the dangerous code runs in a process the sandbox never sees.




