ON
← Back to feed
AI agents automatically execute git malware when they start
Germany💻 Technology8 hr. ago

AI agents automatically execute git malware when they start

The security firm Manifold has identified a vulnerability in manipulated git repositories that could allow malicious code execution through AI coding agents. These repositories contain commands in their configuration that are automatically executed by AI agents when opening them, granting full developer rights outside of sandbox environments without authentication or trust verification. Developers become victims as soon as they open such a repository. When opening a repository, AI agents often perform background git queries like 'git status' or 'git diff', using the complete local git configuration outside of sandboxing before any trust approval. The 'fsmonitor' feature in git allows external commands to be executed, which can be exploited if the command is malicious. Cloning, pulling, or fetching from remote repositories does not pose a risk, but receiving a repository as a zip file from colleagues and importing it into the system can be problematic. Manifold informed several developers of this vulnerability, but some have yet to patch it, including Qwen and Grok. Anthropic addressed the 'fsmonitor' issue but not a similar one related to 'claude ultraview'. Developers are advised,

Go to the primary sources (1)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenter8 hr. ago
AI agents automatically execute git malware when they start

The security firm Manifold has identified a vulnerability in manipulated git repositories that could allow malicious code execution through AI coding agents. These repositories contain commands in their configuration that are automatically executed by AI agents when opening them, granting full developer rights outside of sandbox environments without authentication or trust verification. Developers become victims as soon as they open such a repository. When opening a repository, AI agents often perform background git queries like 'git status' or 'git diff', using the complete local git configuration outside of sandboxing before any trust approval. The 'fsmonitor' feature in git allows external commands to be executed, which can be exploited if the command is malicious. Cloning, pulling, or fetching from remote repositories does not pose a risk, but receiving a repository as a zip file from colleagues and importing it into the system can be problematic. Manifold informed several developers of this vulnerability, but some have yet to patch it, including Qwen and Grok. Anthropic addressed the 'fsmonitor' issue but not a similar one related to 'claude ultraview'. Developers are advised,

Bias read (Center): The article discusses a technical vulnerability in software development tools and provides mitigation strategies. It does not involve political figures, policies, or contentious issues. The content is purely technical and neutral in tone.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories