Threat · curated 14 Aug 2026
Malicious .git Configurations: A Risk for AI
First reported · updated · 5 reports nist.gov
Coverage timeline
Why it matters
AI coding agents' automatic git metadata collection creates a pre-prompt code-execution path that bypasses their permission and trust safeguards, meaning merely opening an attacker-supplied repository can fully compromise a developer's machine and leak provider API keys.
Malicious repository .git/config files that set core.fsmonitor let AI coding agents execute attacker-controlled code outside their sandbox and before any trust prompt or model call. The flaw affects Block's goose (CVE-2026-72718, fixed in 1.44.0), OpenAI Codex CLI/Desktop (CVE-2026-19592), and Anthropic's Claude Code CLI (patched in v2.0.71), where each agent invokes git to gather repo metadata/diffs without stripping repository-local config, causing Git to launch the attacker's filesystem-monitor helper with the user's privileges — enabling file access and exfiltration of environment secrets and API keys.
Summary
A class of code-injection/arbitrary-code-execution vulnerabilities affects AI coding agents that shell out to the system git binary while trusting attacker-controlled repository-local Git configuration. When these agents run git operations to gather context, a malicious .git/config that sets core.fsmonitor to a command causes Git to execute that command on the host, outside the agent's sandbox and permission model.[0][20][31]
CVE-2026-72718 in goose (fixed in 1.44.0, CVSS 4.0 7.0 HIGH, CWE-94) triggers arbitrary command execution during `goose review`'s `git diff HEAD` before goose ever contacts a model and without any prompt, tool approval, or trust prompt. CVE-2026-19592 in OpenAI Codex CLI/Desktop launches the attacker's filesystem-monitor helper during automatic metadata collection outside the Codex sandbox and without approval. Sonar's research showed the same git-project-config path let Claude Code CLI execute code before the user clicked 'trust', patched by Anthropic in v2.0.71.[0][20][31]
Attack chain
- Delivery: The attacker distributes a repository with its .git/config preserved via a mechanism that keeps repository-local configuration, such as a zip/tarball archive, a USB drop, or a network share, since a standard git clone does not preserve the source's local configuration.[20]
- Trigger / context gathering: The victim opens or runs the AI coding agent inside the malicious repository. The agent invokes git operations (e.g., goose's `git diff HEAD`, or Codex's metadata collection) without stripping or disabling the repository-local core.fsmonitor configuration.[0][20]
- Execution: Git spawns the attacker-controlled core.fsmonitor helper during the index refresh/status query, executing arbitrary code with the user's privileges outside the agent's sandbox and without triggering the tool-approval or trust prompt.[0][20][31]
- Impact: The attacker's code runs with the user's privileges and environment, allowing file access, modification, or deletion and exfiltration of environment secrets and provider API keys.[0][20]
Disclosure timeline
| Date | Event |
|---|---|
| 2025-12-16 | Anthropic patched the Claude Code CLI arbitrary-code-execution issues (including execution via git project config) in v2.0.71.[31] |
| 2026-04-30 | Sonar (Yaniv Nizry) published research detailing how Claude Code CLI executed code before the user clicked 'trust'.[31] |
| 2026-08-10 | CVE-2026-72718 (goose) published to the NVD by GitHub, Inc.; CISA-ADP later modified the record adding the GHSA advisory and an SSVC assessment (PoC exploitation, not automatable, total technical impact).[0] |
| 2026-09-01 | CVE-2026-19592 (OpenAI Codex CLI) published to the NVD.[20] |
| 2026-09-03 | SentinelOne published its vulnerability-database entry for CVE-2026-19592.[20] |
How it works
Git's core.fsmonitor setting specifies an external filesystem-monitor helper program that Git launches to accelerate status queries; the value is a trusted execution path in Git. AI coding agents that shell out to git treat repository-local .git/config as inert data and fail to override or unset core.fsmonitor before invoking git, so the helper executes as a side effect of routine metadata reads.[20]
In goose, `goose review` calls the system git binary to gather a diff without removing attacker-controlled Git configuration. A .git/config setting `[core] fsmonitor = <command>` causes Git to run that command during the index refresh performed by `git diff HEAD`. The vulnerable invocations are built by git_command() in crates/goose-cli/src/commands/review/handler.rs and used by touched_files() and collect_diff() for `git diff --name-only HEAD` and `git diff HEAD`. Because the git process is not sandboxed and is outside goose's tool-permission model, commands run with the user's privileges and environment, enabling file access/modification and secret and API-key exfiltration, before any model interaction or approval.[0]
In OpenAI Codex CLI/Desktop the helper runs outside the Codex command sandbox and does not trigger the user-approval prompt that normally gates command execution. Because a standard git clone does not preserve the source repository's local configuration, exploitation requires delivering the repository with .git/config intact (archive, USB, or network share).[20]
Affected versions and patch status
| Product | Affected | Patch status |
|---|---|---|
| goose (aaif-goose) | All versions prior to 1.44.0 | Fixed in version 1.44.0[0] |
| OpenAI Codex CLI (Windows, macOS, Linux) and Codex Desktop (Windows, macOS) | Versions that collect Git metadata without disabling repository-local core.fsmonitor (CVE-2026-19592) | Fix version not stated in available evidence; update to the latest release[20] |
| Anthropic Claude Code CLI | Versions prior to v2.0.71 | Fixed in v2.0.71 (patched by Anthropic as of December 16, 2025)[31] |
Key takeaways
- AI agent tooling that shells out to git can inherit git's own code-execution features (such as core.fsmonitor) as an injection vector, executing attacker-controlled commands outside the agent's permission and sandbox model.[0][20]
- The exploit runs during routine context/metadata gathering, before any model interaction and without user approval, so trust prompts and tool-permission controls do not mitigate it; fixes work by stripping or disabling attacker-controlled Git configuration.[0][20][31]
- This is a recurring cross-vendor pattern rather than an isolated bug: goose, OpenAI Codex, and Anthropic Claude Code were each affected by the same class of trusting repository-local Git configuration.[0][20][31]
Defensive actions
- Upgrade goose to version 1.44.0 or later.: Version 1.44.0 strips attacker-controlled Git configuration before running the review diff, eliminating the code-injection path.[0]
- Update Anthropic Claude Code CLI to v2.0.71 or later.: v2.0.71 fixes the arbitrary-code-execution issues, including execution via git project config, that bypassed the trust dialog.[31]
- Do not open, review, or run AI coding agents inside untrusted repositories that retain their .git/config, especially those delivered as archives, USB drops, or network shares.: A preserved .git/config with a core.fsmonitor command triggers arbitrary command execution during the agent's git context gathering, outside the sandbox and without an approval or trust prompt.[0][20][31]
Changelog
- Expanded scope from a single goose CVE to a cross-vendor weakness class: added OpenAI Codex CLI/Desktop (CVE-2026-19592) and Anthropic Claude Code CLI (patched v2.0.71) as additional AI coding agents vulnerable to attacker-controlled git core.fsmonitor execution.[20][31]
- Added attack-chain and delivery details from Codex research, notably that a standard git clone does not preserve .git/config, so exploitation requires archive, USB, or network-share delivery.[20]
- Added disclosure-timeline events for Anthropic's December 16, 2025 patch, Sonar's April 30, 2026 research publication, and the September 2026 Codex CVE publication and SentinelOne write-up.[31][20]