A single Git config key runs code in 7 coding agents. The 2022 patch… — prompt 🤖 AI News — TG.ME

🚨🔥 A single Git config key runs code in 7 coding agents. The 2022 patch doesn't stop it.

Drop a malicious `.git/config` with `core.fsmonitor` set and Claude Code, Codex, Cursor, Grok and others execute attacker code before any trust prompt, sandbox, or model call kicks in.

No submitted prompt. No approval. Just opening the repo.

Grith published the full breakdown. If you're shipping agents that touch user repos, read it now.
grith.ai
A Git Config Key Ran Code in Seven Coding Agents. The 2022 Fix Does Not Stop It.
core.fsmonitor turns a line of repository config into a shell command. Git shipped an opt-in mitigation in 2022 and it is widely cited as the answer. I reproduced the attack in three configurations: the 2022 setting does not block the path that hits AI coding…
September 9, 2026 591 1