CVE-2026-19592: Git Config Flaw Lets Attackers Run Code in Codex
Manifold Security disclosed GitSpawn, a class of eight vulnerabilities across seven AI coding agents — including Claude Code, Codex, Cursor, Qwen Code, and Grok Build — in which a malicious `.git/config` file using the `core.fsmonitor` directive causes agents to execute attacker-controlled commands at session startup, outside any sandbox or approval prompt. The attack requires the target to open a repository with its `.git` directory intact, achievable via archives, USB drives, or shared folders rather than standard git clones. Four agents remained unpatched at publication, with OpenAI issuing three CVEs for Codex on the same day the research dropped.