AINewsnow

CVE-2026-19592: Git Config Flaw Lets Attackers Run Code in Codex

This story is from 2026-09-04. It is preserved in the archive; the latest stories are on the live feed.

Forensic Summary Manifold Security disclosed GitSpawn, a class of eight vulnerabilities across seven AI coding agents — including Claude Code, Codex, Cursor, Qwen Code, and Grok Build — in which a malicious .git/config file using the core.fsmonitor directive causes agents to execute attacker-contro…

Read the full story at DEV Community — AI ↗

Timeline · 1 report

  1. 2026-09-04 14:31 · DEV Community — AI
    CVE-2026-19592: Git Config Flaw Lets Attackers Run Code in Codex

More stories

  1. A company ran 8 identical AI societies for weeks with different models and just published what happened. Some of it is genuinely unsettling. — r/ArtificialInteligence
  2. Pay $39.99 once to put ChatGPT, Claude, Gemini, and more in a single workspace for life — Mashable AI
  3. The cloud outage that should terrify the CIO — InfoWorld AI
  4. Ho creato un piccolo benchmark "test nascosti + revisione del codice" e l'ho eseguito su Claude Sonnet 5, Claude Opus 4.6 e una versione locale di Qwen 3.8 27B (Unsloth Q6 - Qwen3.8-27B-UD-Q6_K.gguf). Risultati + cosa li ha effettivamente differenziati — r/LocalLLM
  5. Getting more accurate results - personalizations — r/ArtificialInteligence
  6. Agentic Orchestration with Local and Cloud Models — r/LocalLLM
  7. Best workflow to orchestrate local LLMs (Qwen 27B) + Cloud subscriptions (Claude/Codex) without burning tokens? — r/LocalLLM
  8. 4-AI relay: ChatGPT drafted, Muse reviewed, Grok and Claude checked the work — every step in the open — r/OpenAI

Get the daily brief of stories like this at 6:30 every morning →