[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f23GZ5IJK7vfneQd3Oetmnm_oZk9fsWqupYlGMNOj5vU":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"7a864caf-e447-4958-8439-a0645aaa3d62","malicious-git-configs-let-attackers-hijack-ai-coding-agents","ce2f0c49-27b5-46bf-b125-c4c2afa7a65e","Malicious .git Configs Let Attackers Hijack AI Coding Agents","AI coding agents such as Claude, Codex, and Cursor can be manipulated into executing attacker-controlled code by embedding malicious directives inside a repository's .git\u002Fconfig file. The root cause is insufficient validation and sandboxing of Git configuration data before AI agents act on it, allowing repository metadata to become an attack surface. This is particularly dangerous because the exploit bypasses sandbox protections and approval prompts that users expect to serve as safety gates. With four of eight identified vulnerabilities still unpatched at the time of publication, developers using these tools against untrusted repositories remain exposed. The broader risk is that AI agents introduce new trust boundaries that vendors and developers have not yet fully hardened.","**Immediate actions:**\n- Audit all AI coding agent installations and apply any available patches or updates immediately.\n- Avoid cloning or opening untrusted repositories with AI coding agents until vendors confirm fixes.\n- Strip or inspect .git directories before processing external repositories in AI-assisted workflows.\n\n**Long-term improvements:**\n- Establish a formal policy requiring security review of AI development tools before organizational adoption.\n- Work with vendors to implement strict allowlisting of permissible Git configuration directives within AI agent runtimes.\n- Maintain an inventory of all AI coding tools in use and subscribe to their security advisories for rapid patch response.\n\n**Detection measures:**\n- Monitor AI agent processes for unexpected child process spawning or outbound network connections during repository operations.\n- Implement file integrity monitoring on .git\u002Fconfig files within developer workstations and CI\u002FCD pipeline runners.\n- Log and alert on any AI agent actions that invoke shell commands or external scripts outside of approved project directories.",[12,13,14,15,16,17,18,19,20],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 7: Continuous Vulnerability Management","CIS Control 16: Application Software Security","NIST SP 800-53 CM-6: Configuration Settings","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 SA-11: Developer Testing and Evaluation","NIST SP 800-218 (SSDF) PW.6: Sanitize All Inputs","OWASP Top 10: A05 Security Misconfiguration","OWASP Top 10: A08 Software and Data Integrity Failures","published","2026-09-02T16:22:11.524029+00:00","2026-09-02T16:22:11.429+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fmalicious-git-configs-can-make-claude.html","malicious-git-configs-can-make-claude-codex-cursor-and-other-ai-agents-run-attac-335721","Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":42,"name":43,"slug":44,"description":45,"color":46},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]