Security researchers disclosed a vulnerability class called GitSpawn affecting Claude Code, OpenAI Codex, Cursor, Grok Build, and several other AI coding agents. The flaw lets an attacker-supplied .git configuration file silently execute commands as soon as the agent runs a routine background git command like git status or git diff on the repository, with no prompt or approval required. Exploitation requires the .git directory to arrive intact via a shared archive, sync folder, or USB drive rather than a normal git clone. As of September 1, 2026, patches had shipped for Goose, Claude Code, and Cursor, while Hermes Agent, Qwen Code, Grok Build, and a second code path in Claude Code remained vulnerable.