Security & Compliance
September 7, 2026GitSpawn: a malicious repo can hijack your coding agent
A repository that arrives as a zip, sync folder or USB stick can execute attacker code the moment a CLI coding agent opens it, before any approval prompt and outside the agent sandbox. Manifold Security's GitSpawn disclosure covers eight findings across Claude Code, Codex, Cursor, Goose, Hermes Agent, Qwen Code and Grok Build, with four unpatched at publication.
GitSpawn
Coding Agents
Claude Code
Supply Chain Security
Git
NIS2
Developer Security
AI Agents
Vulnerability Disclosure
By Falak Mahmood