
GitSpawn Flaws Let Malicious Repositories Execute Code in Claude Code, Codex, Cursor and Grok
A newly disclosed class of vulnerabilities, dubbed GitSpawn, can allow a booby-trapped software repository to silently execute code on a developer’s machine the moment it is opened with an AI coding agent. The attack requires no prompt, approval click, or other user interaction. In some cases, the malicious command can run before a developer has […]
The post GitSpawn Flaws Let Malicious Repositories Execute Code in Claude Code, Codex, Cursor and Grok appeared first on Cyber Security News.