#configs


Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

Sep 3, 2026 // 00:22

Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository’s own Git configuration names a command that the […]

Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs

Jun 26, 2026 // 16:58

A high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer’s cloud credentials. The path was short: a developer […]