GitSpawn Exposes Persistent Git Config Execution Risks in Coding Agents
Manifold Security has published GitSpawn, a report uncovering eight vulnerabilities across seven coding agents that allow arbitrary code execution simply by opening a received folder.
The attack leverages Git's core.fsmonitor configuration key stored in .git/config. This setting defines a command that Git automatically runs during index refreshes triggered by operations such as git status or git diff. Coding agents invoke these commands in the background immediately after opening a directory to build context, executing the payload before any user approval or prompt.
The researcher demonstrated the exploit by setting core.fsmonitor to a malicious script and confirming execution with a single git status command. Payloads ran even in the absence of any explicit user action beyond opening the folder.
Partial Patches Leave Broader Risks
Vendors responded with targeted fixes. Claude Code closed the core.fsmonitor vector in version 2.1.196, and similar patches were applied to Codex, Cursor, and Goose. However, these mitigations only prevent the agent from invoking Git with dangerous configuration values. Manual execution of git status or integration with build scripts, editors, and CI systems still triggers the payload.
Additional issues compound the problem. Manifold Security reported a second bypass path in Claude Code that remained open on version 2.1.252. Agents including Qwen Code, Grok Build, and Hermes Agent stayed unpatched as of the report date. A separate vector involving nested bare repositories was assigned CVE-2026-45033 and affected GitHub Copilot CLI until version 1.0.43.
The class of vulnerability is not new. VS Code addressed similar risks in 2021 through workspace trust prompts, yet the arrival of autonomous coding agents effectively reset those protections.
Stroq Tool for Pre-Opening Inspection
To address the gap, the researcher released Stroq, an open-source Apache-2.0 tool that scans repositories for dangerous settings before they are accessed. The command checks .git/config for executable values, .gitattributes, .husky hooks, postinstall scripts, and nested bare repositories.
Environment variable overrides can also neutralize the vectors at runtime by forcing core.fsmonitor to false and disabling automatic bare repository discovery. The tool is intended for use in pre-commit hooks and CI pipelines.
Related articles
Microsoft Fixes CVE-2026-96940 in Exchange Server Allowing Authenticated Mailbox Access
Microsoft has patched CVE-2026-96940, a CVSS 8.8 vulnerability in Exchange Server that lets any authenticated user read other users' mailboxes without administrative rights. The flaw exposes full message content and attachments including contracts, spreadsheets, and sensitive documents. Affected on-premises versions include Exchange Server Subscription Edition RTM, Exchange 2016 CU23, Exchange 2019 CU15, and Exchange 2019 CU14. Exchange Online users are protected because the fix was applied server-side. Microsoft rates exploitation as likely but reports no confirmed attacks in the wild at disclosure time. The issue turns a single low-privilege credential into broad access to executive, legal, and financial correspondence.
New Spectre-v2 Variant Uses JIT Compiler Branch Target Reuse for Cross-Process Data Extraction
Researchers from the Netherlands and Italy have published a paper detailing a fresh Spectre-v2 attack that reuses branch predictor state instead of injecting new instructions. The technique leverages the JIT compiler cBPF inside the Linux kernel to train the branch target predictor, enabling speculative execution that leaks sensitive data such as hashed root passwords. Practical demonstrations extracted credentials from the su process in an average of three to five minutes on AMD, Intel, and ARM processors. Partial success was shown with SpiderMonkey in Firefox and GraalVM, although realistic end-to-end attacks were not achieved with those engines. The work also covers additional topics including forensic detection of attacks against 1C servers, a record Debian Linux kernel patch set, zero-day fixes in TeamViewer and Apple Core Graphics, and critical flaws in Dell Container Storage Modules.
Critical CVE-2026-21589 Affects Eight Atlassian Products with CVSS 9.3 Score
Atlassian has disclosed a critical vulnerability tracked as CVE-2026-21589 that impacts eight of its products. The flaw allows unauthenticated access to specific files located in the web application's root directory when an attacker already knows the file name and path. Products affected include Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian rates the issue Critical with a CVSSv4.0 base score of 9.3 and warns that Data Center editions face elevated risk due to potential exposure of sensitive files. The company released patches for all affected products and urges immediate updates, while also providing mitigation steps and indicators of compromise for organizations unable to patch right away.
Fortinet Releases FortiMail Updates to Patch Zero-Day CVE-2026-104286
Fortinet has begun distributing updates for its FortiMail email security product to address the zero-day vulnerability CVE-2026-104286. The flaw allows unauthenticated attackers to write arbitrary files to the system by sending specially crafted HTTP requests. The company first published a security advisory on October 1, 2026, confirming active exploitation and providing Indicators of Compromise while preparing fixes. On October 5, 2026, Fortinet updated the advisory and released patched versions including FortiMail 8.0.2, 7.6.7, and 7.4.9. Organizations still running the 7.2 branch are advised to migrate to the 7.4 branch or later to obtain protection. The advisory reference is FG-IR-26-175.