Ask a coding agent to look at a repository and one of the first things it does is run git status or git diff. Few commands look more harmless. That is exactly what made GitSpawn work.
What happened
Manifold Security described an attack class built on Git's core.fsmonitor setting. It is a performance setting, and its value is a command that Git runs to find changed files. If a repository you receive has a malicious .git/config, then any git status or git diff runs the attacker's command with your privileges. The coding agent never has to be tricked into doing anything unusual.
- Reported as affected: goose, Claude Code, Cursor, Codex CLI and Desktop, Hermes Agent, Qwen Code and Grok Build.
- Fixed versions, per the report: goose 1.44.0 and Codex 0.131.0. Cursor was patched. Claude Code received a partial fix, with a second path reported as still live in a later version.
- Unpatched at the time of reporting: Hermes Agent, Qwen Code and Grok Build.
- The timing is the worst part. In some agents the payload fired before the workspace-trust prompt was accepted. In one it fired before authentication, and in another on the first keystroke.
- OpenAI published CVEs on the day of disclosure, including CVE-2026-19592.
The lesson: trust prompts are not a boundary if something runs before them
Many teams rely on the agent's own 'do you trust this folder?' dialog as their line of defence. GitSpawn shows why that is fragile. The dangerous command was not typed by the agent or approved by the user. It was triggered by a routine tool the agent calls on its own.
# Disable fsmonitor globally (recommended mitigation from the research)
git config --global core.fsmonitor false
# Check a received repository before opening it with an agent
grep -n fsmonitor path/to/repo/.git/configWhere a governance layer helps
DarkControl checks every shell command, file write and network call an agent makes against a central policy. It doesn't replace patching, but it closes the gaps around it:
- Deny or ask whenever an agent tries to change git configuration, such as editing .git/config or running git config to set core.fsmonitor or other hook-style settings. An agent should rarely need to do either.
- Ask before agents run commands in repositories outside your approved workspace paths, for example in a Downloads folder or an extracted archive.
- Deny outbound connections to unknown destinations. A command that runs but can't send anything home does much less damage.
- Keep an immutable audit log of every git command every agent ran, so that after a disclosure like this you can check which machines opened which repositories, and when.
Source: The Hacker News, 'Malicious Git configs can make Claude Code and other agents run attacker commands', September 2026: https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html
Find out which repositories your agents are really working in. Start a free 7-day watch-only audit on up to 10 devices. Nothing is blocked.