Malicious .git Configs Let Attackers Hijack AI Coding Agents
AI coding agents such as Claude, Codex, and Cursor can be manipulated into executing attacker-controlled code by embedding malicious directives inside a repository's .git/config file. The root cause is insufficient validation and sandboxing of Git configuration data before AI agents act on it, allowing repository metadata to become an attack surface. This is particularly dangerous because the exploit bypasses sandbox protections and approval prompts that users expect to serve as safety gates. With four of eight identified vulnerabilities still unpatched at the time of publication, developers using these tools against untrusted repositories remain exposed. The broader risk is that AI agents introduce new trust boundaries that vendors and developers have not yet fully hardened.
Tactical Insight
Immediate actions
- Audit all AI coding agent installations and apply any available patches or updates immediately.
- Avoid cloning or opening untrusted repositories with AI coding agents until vendors confirm fixes.
- Strip or inspect .git directories before processing external repositories in AI-assisted workflows.
Long-term improvements
- Establish a formal policy requiring security review of AI development tools before organizational adoption.
- Work with vendors to implement strict allowlisting of permissible Git configuration directives within AI agent runtimes.
- Maintain an inventory of all AI coding tools in use and subscribe to their security advisories for rapid patch response.
Detection measures
- Monitor AI agent processes for unexpected child process spawning or outbound network connections during repository operations.
- Implement file integrity monitoring on .git/config files within developer workstations and CI/CD pipeline runners.
- Log and alert on any AI agent actions that invoke shell commands or external scripts outside of approved project directories.