CVE-2026-19592: Git Config Flaw Lets Attackers Run Code in Codex
This story is from 2026-09-04. It is preserved in the archive; the latest stories are on the live feed.
Forensic Summary Manifold Security disclosed GitSpawn, a class of eight vulnerabilities across seven AI coding agents — including Claude Code, Codex, Cursor, Qwen Code, and Grok Build — in which a malicious .git/config file using the core.fsmonitor directive causes agents to execute attacker-contro…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-04 14:31 · DEV Community — AI
CVE-2026-19592: Git Config Flaw Lets Attackers Run Code in Codex