חזרה לפיד
newsמקור: The Hacker News2.9.2026

תצורות .git זדוניות מאפשרות לסוכני AI להריץ קוד תוקף

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

תצורות .git זדוניות מאפשרות לסוכני AI להריץ קוד תוקף

◆ סיכום AI

חברת Manifold Security חשפה שמונה ליקויי אבטחה בסוכני קידוד מבוססי AI כגון Claude ו-Codex. ליקויים אלו מאפשרים לתצורות .git זדוניות להריץ פקודות על מכונת המפתח מחוץ לסביבת הסנדבוקס של הסוכן, מה שחושף את המפתחים לסיכוני אבטחה חמורים. ארבעה מהם עדיין לא תוקנו.

# מהמקור

Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive

#ai-security#supply-chain#code-security#git-vulnerabilities
קרא במקור