Security researchers at Manifold Security have disclosed eight vulnerabilities affecting seven popular command-line AI coding agents, including Claude, Codex, and Cursor. The flaws stem from how these agents interact with a repository's Git configuration. If a repository contains a malicious configuration naming a specific command, the AI agent may execute that command on the developer's local machine without requesting approval or alerting the user.
The exploitation occurs because the commands are executed as the local user and operate outside of the AI agent's sandbox environment. At the time of publication, four of these security flaws remained unpatched. To trigger the exploit, a developer must simply open or interact with a compromised repository using a vulnerable AI agent, allowing the attacker-defined code to run with the developer's permissions.
This discovery highlights a significant attack vector targeting software supply chains and developer environments. By embedding malicious instructions within standard configuration files, attackers can bypass traditional sandboxing measures intended to isolate AI processes. The risk is particularly high for teams that frequently clone external repositories or use third-party code for development tasks.
IT leaders and operations managers should verify the patch status of AI tools used within their development teams and consider implementing stricter policies regarding the use of AI agents with untrusted repositories. Monitoring for unusual local command execution originating from development tools can help mitigate the risk of unauthorized access or data exfiltration.
The BroadVision view
These vulnerabilities demonstrate that even advanced AI productivity tools can introduce unforeseen risks into the software development lifecycle. Mid-market IT teams must balance the speed of AI adoption with rigorous governance over developer environments and repository access. Implementing comprehensive managed IT services can help organizations maintain visibility and security over evolving developer toolchains. https://broadvision.com/managed-it-services Teams weighing what to change first can review BroadVision's managed IT services.
