SECURITY·중요도 9·2026. 09. 02.·The Hacker News
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
── KO ──────────────────
악성 .git 구성으로 AI 에이전트가 공격자 코드를 실행할 수 있는 보안 취약점이 발견되었습니다.
Manifold Security는 7개 AI 코딩 에이전트에서 발견된 8개의 보안 취약점을 공개했습니다. 이 취약점은 저장소의 Git 구성 파일이 개발자의 머신에서 실행될 명령을 지정할 수 있도록 합니다. 네 가지의 취약점은 아직 패치되지 않았으며, 공격자가 코드 실행을 위해 특별한 승인이 필요하지 않습니다.
── EN ──────────────────
Malicious .git configurations can allow AI agents to execute attacker code on user machines.
Manifold Security disclosed eight security vulnerabilities in seven command-line AI coding agents. These flaws allow a repository's Git configuration to specify a command that the agent executes on the developer's machine. Four of these vulnerabilities remain unpatched at the time of publication, with exploitation not requiring user approval.