Skip to finding
§
High
RCE — coding agents
Provisional
CVE-2026-72718

A repository received as files can make multiple coding agents run attacker code before trust or approval.

The malicious .git configuration must survive delivery; an ordinary clone does not carry it.

Affects

Claude Code, Goose, Hermes Agent, Qwen Code, Grok Build, Codex and Cursor command-line AI coding agents on developer workstations.

What it enables

Pre-trust arbitrary code execution as the developer

Attacker prepares a repository directory whose .git/config names an attacker-controlled helper through core.fsmonitor or another command-bearing Git setting→↓The directory reaches the victim through an archive, shared drive, synchronization folder or removable media, preserving .git/config→↓The victim opens the folder or requests a review in an affected coding agent→↓The agent automatically invokes git status, git diff or equivalent context-gathering before its trust prompt, authentication step or approval boundary→↓Git refreshes its index and executes the repository-selected helper outside the agent sandbox with the developer's privileges
Why this matters

The changed boundary is execution before the agent asks for trust, authentication, or command approval across multiple products.

Detail and 1 source
Required access

Deliver a repository directory whose .git directory and attacker-controlled helper survive, then induce the victim to open or review it with an affected coding agent; an ordinary git clone does not preserve the malicious local configuration

Affected versions

Qwen Code 0.22.3 confirmed affected on 2026-09-01 and unpatched at publication, Grok Build 1.0.13 confirmed affected on 2026-09-01 and unpatched at publication, Hermes Agent 0.21.0 confirmed affected on 2026-09-01 and unpatched at publication, Claude Code ultrareview path confirmed affected on 2.1.252 and unpatched at publication, Claude Code core.fsmonitor path confirmed on 2.1.193 and fixed by 2.1.196, Goose 1.41.0 affected and fixed in 1.44.0, Codex and Cursor historical versions were affected and patched before publication; the primary research did not state exact ranges

Proof of concept

Demonstrated by the researcher

The attacker prepares a directory whose .git/config selects a helper through core.fsmonitor or another command-bearing Git setting. The directory must arrive through an archive, shared drive, synchronization folder, or removable media with both the local configuration and helper intact.

When an affected agent gathers context with git status, git diff, or an equivalent command, Git executes the selected helper outside the sandbox as the developer. Manifold’s September 1 retest found current unpatched paths still exposed, so received repositories should be treated as executable content before an agent opens them.

Evidence
Manifold Security's original research explains the delivery constraint, sink and agent-by-agent demonstrationsManifold retested every unpatched path against a current release on 2026-09-01
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 2, 2026