תצורות .git זדוניות מאפשרות לסוכני AI להריץ קוד תוקף
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

◆ סיכום AI
חברת Manifold Security חשפה שמונה ליקויי אבטחה בסוכני קידוד מבוססי AI כגון Claude ו-Codex. ליקויים אלו מאפשרים לתצורות .git זדוניות להריץ פקודות על מכונת המפתח מחוץ לסביבת הסנדבוקס של הסוכן, מה שחושף את המפתחים לסיכוני אבטחה חמורים. ארבעה מהם עדיין לא תוקנו.
# מהמקור
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive