Threat · curated 14 Aug 2026

Malicious .git Configurations: A Risk for AI

Dossier

Coverage timeline

14 Aug 2026nist.gov 1 Sep 2026manifold.securitythehackernews.comsecnews.gr 16 Sep 2026shattered.io

Why it matters

AI coding agents' automatic git metadata collection creates a pre-prompt code-execution path that bypasses their permission and trust safeguards, meaning merely opening an attacker-supplied repository can fully compromise a developer's machine and leak provider API keys.

Malicious repository .git/config files that set core.fsmonitor let AI coding agents execute attacker-controlled code outside their sandbox and before any trust prompt or model call. The flaw affects Block's goose (CVE-2026-72718, fixed in 1.44.0), OpenAI Codex CLI/Desktop (CVE-2026-19592), and Anthropic's Claude Code CLI (patched in v2.0.71), where each agent invokes git to gather repo metadata/diffs without stripping repository-local config, causing Git to launch the attacker's filesystem-monitor helper with the user's privileges — enabling file access and exfiltration of environment secrets and API keys.

vuln-research

Summary

A class of code-injection/arbitrary-code-execution vulnerabilities affects AI coding agents that shell out to the system git binary while trusting attacker-controlled repository-local Git configuration. When these agents run git operations to gather context, a malicious .git/config that sets core.fsmonitor to a command causes Git to execute that command on the host, outside the agent's sandbox and permission model.[0][20][31]

CVE-2026-72718 in goose (fixed in 1.44.0, CVSS 4.0 7.0 HIGH, CWE-94) triggers arbitrary command execution during `goose review`'s `git diff HEAD` before goose ever contacts a model and without any prompt, tool approval, or trust prompt. CVE-2026-19592 in OpenAI Codex CLI/Desktop launches the attacker's filesystem-monitor helper during automatic metadata collection outside the Codex sandbox and without approval. Sonar's research showed the same git-project-config path let Claude Code CLI execute code before the user clicked 'trust', patched by Anthropic in v2.0.71.[0][20][31]

Attack chain

  1. Delivery: The attacker distributes a repository with its .git/config preserved via a mechanism that keeps repository-local configuration, such as a zip/tarball archive, a USB drop, or a network share, since a standard git clone does not preserve the source's local configuration.[20]
  2. Trigger / context gathering: The victim opens or runs the AI coding agent inside the malicious repository. The agent invokes git operations (e.g., goose's `git diff HEAD`, or Codex's metadata collection) without stripping or disabling the repository-local core.fsmonitor configuration.[0][20]
  3. Execution: Git spawns the attacker-controlled core.fsmonitor helper during the index refresh/status query, executing arbitrary code with the user's privileges outside the agent's sandbox and without triggering the tool-approval or trust prompt.[0][20][31]
  4. Impact: The attacker's code runs with the user's privileges and environment, allowing file access, modification, or deletion and exfiltration of environment secrets and provider API keys.[0][20]

Disclosure timeline

DateEvent
2025-12-16Anthropic patched the Claude Code CLI arbitrary-code-execution issues (including execution via git project config) in v2.0.71.[31]
2026-04-30Sonar (Yaniv Nizry) published research detailing how Claude Code CLI executed code before the user clicked 'trust'.[31]
2026-08-10CVE-2026-72718 (goose) published to the NVD by GitHub, Inc.; CISA-ADP later modified the record adding the GHSA advisory and an SSVC assessment (PoC exploitation, not automatable, total technical impact).[0]
2026-09-01CVE-2026-19592 (OpenAI Codex CLI) published to the NVD.[20]
2026-09-03SentinelOne published its vulnerability-database entry for CVE-2026-19592.[20]

How it works

Git's core.fsmonitor setting specifies an external filesystem-monitor helper program that Git launches to accelerate status queries; the value is a trusted execution path in Git. AI coding agents that shell out to git treat repository-local .git/config as inert data and fail to override or unset core.fsmonitor before invoking git, so the helper executes as a side effect of routine metadata reads.[20]

In goose, `goose review` calls the system git binary to gather a diff without removing attacker-controlled Git configuration. A .git/config setting `[core] fsmonitor = <command>` causes Git to run that command during the index refresh performed by `git diff HEAD`. The vulnerable invocations are built by git_command() in crates/goose-cli/src/commands/review/handler.rs and used by touched_files() and collect_diff() for `git diff --name-only HEAD` and `git diff HEAD`. Because the git process is not sandboxed and is outside goose's tool-permission model, commands run with the user's privileges and environment, enabling file access/modification and secret and API-key exfiltration, before any model interaction or approval.[0]

In OpenAI Codex CLI/Desktop the helper runs outside the Codex command sandbox and does not trigger the user-approval prompt that normally gates command execution. Because a standard git clone does not preserve the source repository's local configuration, exploitation requires delivering the repository with .git/config intact (archive, USB, or network share).[20]

Affected versions and patch status

ProductAffectedPatch status
goose (aaif-goose)All versions prior to 1.44.0Fixed in version 1.44.0[0]
OpenAI Codex CLI (Windows, macOS, Linux) and Codex Desktop (Windows, macOS)Versions that collect Git metadata without disabling repository-local core.fsmonitor (CVE-2026-19592)Fix version not stated in available evidence; update to the latest release[20]
Anthropic Claude Code CLIVersions prior to v2.0.71Fixed in v2.0.71 (patched by Anthropic as of December 16, 2025)[31]

Key takeaways

  • AI agent tooling that shells out to git can inherit git's own code-execution features (such as core.fsmonitor) as an injection vector, executing attacker-controlled commands outside the agent's permission and sandbox model.[0][20]
  • The exploit runs during routine context/metadata gathering, before any model interaction and without user approval, so trust prompts and tool-permission controls do not mitigate it; fixes work by stripping or disabling attacker-controlled Git configuration.[0][20][31]
  • This is a recurring cross-vendor pattern rather than an isolated bug: goose, OpenAI Codex, and Anthropic Claude Code were each affected by the same class of trusting repository-local Git configuration.[0][20][31]

Defensive actions

  • Upgrade goose to version 1.44.0 or later.: Version 1.44.0 strips attacker-controlled Git configuration before running the review diff, eliminating the code-injection path.[0]
  • Update Anthropic Claude Code CLI to v2.0.71 or later.: v2.0.71 fixes the arbitrary-code-execution issues, including execution via git project config, that bypassed the trust dialog.[31]
  • Do not open, review, or run AI coding agents inside untrusted repositories that retain their .git/config, especially those delivered as archives, USB drops, or network shares.: A preserved .git/config with a core.fsmonitor command triggers arbitrary command execution during the agent's git context gathering, outside the sandbox and without an approval or trust prompt.[0][20][31]

Changelog

  • Expanded scope from a single goose CVE to a cross-vendor weakness class: added OpenAI Codex CLI/Desktop (CVE-2026-19592) and Anthropic Claude Code CLI (patched v2.0.71) as additional AI coding agents vulnerable to attacker-controlled git core.fsmonitor execution.[20][31]
  • Added attack-chain and delivery details from Codex research, notably that a standard git clone does not preserve .git/config, so exploitation requires archive, USB, or network-share delivery.[20]
  • Added disclosure-timeline events for Anthropic's December 16, 2025 patch, Sonar's April 30, 2026 research publication, and the September 2026 Codex CVE publication and SentinelOne write-up.[31][20]