Opening the Folder Is the Exploit: GitSpawn Turns Untrusted Repos Into RCE Across Seven Coding Agents

In September 2026, Manifold Security published GitSpawn: a single vulnerability pattern that lets an untrusted repository run arbitrary commands in Claude Code, OpenAI Codex, Cursor, Goose, Hermes Agent, Qwen Code and Grok Build — no prompt injection, no jailbreak, no approval dialog. The trigger is opening the folder. The agent runs git status to orient itself, git refreshes its index, and the repository’s own core.fsmonitor setting names the command that runs. Eight findings across seven agents; four were still unpatched at publication, every one re-confirmed on a current release.

This is the same bug class as CVE-2026-102437, which we covered last week — except there the vendor’s wrapper stripped the dangerous settings and missed one, while here most agents stripped nothing at all. And git is under fire from a second direction at once: Plugin4Shell abuses pinned plugin commits to swap malicious code into four of the same agents during automatic updates. Adversa AI’s October roundup, published this week, names git “the single most exercised boundary of the month.”

The mechanism: the agent’s own subprocess, outside every control

Manifold’s researchers, Ax Sharma and Francisco Rosales, started from one question: what does a CLI agent actually do at startup? The answer is context-gathering — branch, modified files, diffs, worktrees — executed as the agent’s own git subprocess, outside the sandbox and outside the tool-permission model. Those calls passed the repository’s .git/config through untouched, and several git settings are command-execution sinks: core.fsmonitor, a documented performance hook for large repos, runs its configured helper on every index refresh. A repository shipping [core] fsmonitor = <command> gets that command executed by git status, git diff, or anything else that touches the working tree — as the developer, with their SSH keys, cloud credentials, shell tokens and every repo on disk in reach.

Delivery is worth stating precisely, because the instinct is wrong: cloning a hostile URL does nothing, and neither do fetch or pull. Git never transports this. The repository must arrive as files with its .git directory inside — a shared zip, a sync folder, a USB stick, a consultant’s handoff. Every proof of concept in the research used a zip. And timing defeats the trust UX entirely: on some agents the payload runs before the workspace-trust prompt, before authentication, even before the first prompt is typed.

Agent by agent: duplicates everywhere, patches in half the cases

  • Goose — goose review built its diff with git diff, passing one config flag and stripping none. Reported 13 July against 1.41.0, fixed in 1.44.0 as CVE-2026-72718 (CVSS 4.0 7.0, scored by the maintainers).
  • Claude Code (core.fsmonitor) — startup git status dropped the marker file while the trust prompt was still awaiting acceptance. Reported 26 June, closed as a duplicate of a report filed the same day, fixed by 2.1.196. Found independently, twice, within hours.
  • Claude Code (ultrareview) — a different sink of the same kind, firing before the review begins. Reported 15 July, closed as a duplicate of an internal ticket, confirmed still unpatched on 2.1.252 on 1 September.
  • Hermes Agent — context-gathering on the first message. Confirmed on 0.18.2, reported the next day, re-confirmed on 0.21.0; the private advisory was never triaged across six contact attempts, and VulnCheck assigned CVE-2026-71963 (CVSS 4.0 8.6). Notably, the NVD record marks versions 0.18.2–0.21.0 affected with a fix commit recorded, and upstream’s own tracker shows the hardening program continuing past publication — issue #126017, closed 1 October, documents the hardened git environment and a dedicated test_gitspawn_config_injection.py suite while closing four missed call sites.
  • Qwen Code — payload executes at startup, before the user has authenticated. Reported 7 July to Alibaba’s response centre and accepted; re-confirmed on 0.22.3, unpatched at publication.
  • Grok Build — fires on the first keystroke of a prompt. An earlier same-class report from 1 July had been closed as informative; Manifold’s 14 July follow-up closed as its duplicate. Re-confirmed on 1.0.13, unpatched at publication.
  • Codex and Cursor — also affected; both reports came back as duplicates of other researchers’ filings and both have since been patched.

The duplicate count is the finding inside the finding: five of Manifold’s reports duplicated independent filings, one same-day. This pattern is being discovered from several directions at once, which means the unpatched instances are being found from several directions too.

Plugin4Shell: git from the other direction

While GitSpawn rides the agent’s own git calls outward, Plugin4Shell rides plugin updates inward. Per Adversa’s October write-up, Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI install pinned plugin commits via git checkout without verifying what landed — so a branch named like the pinned SHA silently substitutes malicious code during automatic updates. Pinning to a hash protects nothing if nothing checks the hash after checkout. Between the two techniques, the agent’s relationship with git is compromised in both directions: the repo’s config executes through the agent’s git, and the agent’s own dependencies arrive through git without verification.

The October roundup: the harness is the vulnerability

Adversa’s “AI coding agent vulnerabilities, October 2026” organises 26 resources and lands a structural verdict worth quoting: cataloguing ten documented attacks on Claude Code, it finds they hit config files, hooks, approval dialogs, MCP tool output, plugin pins and skill packages — not the model. Only two produced CVEs; four were declined by vendors; misleading consent dialogs recur across findings. Read alongside GitSpawn and Plugin4Shell, the month’s bugs cluster in the harness because the harness is the security boundary — model refusals are preferences, harness restrictions are controls.

The surrounding entries reinforce the breadth: CVE-2026-82533 lets a sandboxed agent escape DeepSeek Harness to “danger-full-access” over an unauthenticated loopback API (CVSS 9.4); Codex lost its sandbox twice; OpenCode’s upgrade endpoint allowed cross-origin package installs (fixed 1.18.22); the brig sandbox runner handed host directories to symlink-planting agents; ZCode exfiltrated whole workspaces to cloud storage past its own privacy toggles; and PixelLeak needed no attacker at all — agents unable to attach screenshots to pull requests pushed 13,000+ of them to public repos across 300 organisations.

What to do now

  • Treat every directory as untrusted until proven otherwise. Do not open zips, shared folders or handoffs directly in an agent. Inspect .git/config for core.fsmonitor, core.hooksPath, core.pager and core.editor before the agent ever sees the tree — or open it in a disposable container first.
  • Patch what can be patched. Goose 1.44.0+, Claude Code past 2.1.196, current Codex and Cursor. For Qwen Code, Grok Build, Claude’s ultrareview path and Hermes at or before 0.21.0, assume exposure and check upstream for the fix commits before trusting the startup path.
  • Verify plugin pins, don’t just set them. After updates in Claude Code, Codex, Copilot or Gemini CLI, confirm the checked-out commit matches the pinned SHA. A pin without verification is a comment, not a control.
  • Strip the environment around agent git calls. The Reasonix fix is the template: wrapper-level -c overrides or a scrubbed environment on every git invocation, including the ones that only “read” — status, ls-files, worktree — because reads refresh the index too.
  • Put agent tokens in the rotation plan. Infostealers now harvest Claude, Cursor, Cline and Codex tokens plus MCP configs from predictable paths. A GitSpawn-class execution exposes the full environment, including provider API keys.

Our verification was primary-source-led and static. We read the Manifold Security GitSpawn post (September 2026, updated 1 September, by Ax Sharma and Francisco Rosales) including its per-agent case studies, timeline table and disclosure notes, and report statuses, versions and the duplicate-handling history as published. We pulled the NVD 2.0 records for CVE-2026-72718 (Goose, CVSS 4.0 7.0) and CVE-2026-71963 (Hermes Agent 0.18.2–0.21.0, CVSS 4.0 8.6, fix commit recorded) directly and confirmed the affected products, scores and vectors; the upstream Hermes hardening follow-up is our own check of NousResearch/hermes-agent issue #126017 (filed 28 September 2026, closed 1 October 2026 as completed). Plugin4Shell and the month’s surrounding findings are via Adversa AI’s October 2026 roundup (2 October 2026) and are attributed as such. We did not build a malicious repository, install any agent, or attempt exploitation; severity figures and unpatched-at-publication statuses are the researchers’ own.

Sources: