Urgent.News

What's breaking now, across thousands of outlets.

AI

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

We haven't written up this one. The Hacker News has the full story — the link below goes straight to it.

Read the original at thehackernews.com →

More in AI

A Minimal-Context Take-Home Test for AI Code Reviewers: When More History Hurts

Recent discussions about AI assistants that trust every archived comment raise a practical question for engineering teams: does an AI code reviewer become more accurate when given the full repository…

  • Excessive repository history can lead to inaccurate AI code reviewer feedback
  • Three context configurations tested: full history, diff only, diff + specific comment
  • Human reviewer scored perfect 20/20 on take-home task under optimal conditions

More from Wednesday 2 September →