AI coding agent security had its worst fortnight of 2026 so far. In the space of a few days, researchers published a git config trick that ran code in seven agents before any approval prompt, a plugin pinning flaw that turns background auto-updates into zero-click remote code execution, and a leak of more than 13,000 internal screenshots that agents pushed to public GitHub repositories on their own.
None of these attacks needed a jailbreak or a clever prompt. They went around the model entirely, through git, plugin updaters and the agent’s own helpfulness.
I read the primary write-ups from Manifold Security, Air Security, Straiker, Accomplish and Glow, plus Adversa AI’s October 2 roundup that lists 26 agent security resources from the past month. I have not reproduced any of these exploits myself. Below is what each one does, who has patched, and the changes I would make to a developer setup this week.
GitSpawn: How a Git Config Runs Code in AI Coding Agents
GitSpawn lets an untrusted repository run a program on your machine the moment an AI coding agent runs git status. Manifold Security found it in Claude Code, OpenAI Codex, Cursor, Goose, Hermes Agent, Qwen Code and Grok Build.
The mechanism is old git behaviour meeting new agent habits. Git has config keys that name programs to run. The best known is core.fsmonitor, a performance setting that points at a helper which reports file changes during an index refresh.
Agents gather context constantly. They run git status --porcelain=2 --branch or git diff --name-only HEAD in the background to see what changed, and those commands refresh the index. If the repository’s own .git/config names a malicious fsmonitor program, git runs it with your privileges.
That happens outside the agent’s sandbox and before any approval prompt, because the agent never thought of a status check as a command worth asking about.
There is one important limit. A normal git clone does not copy .git/config, so the repository has to arrive as files with its .git folder intact: a zip, a shared drive, a sync folder or a USB stick. That sounds narrow until you think about how often “here is the repo, take a look” arrives as a zip in a support ticket or a take-home interview task.
Here is the patch status as Manifold published it:
| Agent | Reported | Status |
|---|---|---|
| Claude Code (core.fsmonitor) | 26 June 2026 | Patched in 2.1.196 |
| Cursor | 8 July 2026 | Patched |
| Goose | 13 July 2026 | Patched in 1.44.0 (CVE-2026-72718) |
| OpenAI Codex | 20 July 2026 | Patched |
| Qwen Code | 7 July 2026 | Unpatched, accepted by Alibaba SRC |
| Grok Build | 14 July 2026 | Unpatched |
| Hermes Agent | 20 July 2026 | Unpatched (CVE-2026-71963), no triage after six contacts |
| Claude Code (ultrareview path) | 15 July 2026 | Unpatched |
(Source: Manifold Security GitSpawn disclosure, via Adversa AI’s October 2026 roundup.)
The second Claude Code row is the one I would watch. Manifold says a separate path through ultrareview uses another command-execution key it has not named while it is unpatched, and Anthropic marked the report as a duplicate of an internal ticket.
Manifold’s fix for vendors is one line: pass -c core.fsmonitor=false on the background git calls. For users, the advice is just as short: inspect .git/config before you open a folder with an agent, because any setting that names a program can run it.
Plugin4Shell: Zero-Click RCE Through Plugin Auto-Updates
Plugin4Shell turns a plugin you already trust into malware during a background update, with no click from you. Air Security reported it in Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI.
Agent plugin marketplaces pin plugins to a commit SHA, which feels safe. The flaw is that agents checked out the pinned reference and never confirmed that what they got was actually that commit.
Git resolves names in a way that makes this exploitable. An attacker who controls the plugin repository creates a branch whose name is the pinned SHA, makes it the default, and the checkout lands on the branch instead of the commit. According to Air Security, nothing stops a branch from being named like a hash on many Git hosts, including Bitbucket and self-hosted servers.
There are two attack paths: publish a clean plugin, pass marketplace review, then swap the content; or take over an existing plugin’s repository and push malware to every install on the next update.
| Agent | Plugin4Shell status |
|---|---|
| Claude Code | Patched in 2.1.179 (confirmed 17 June 2026) |
| OpenAI Codex | Patched in 0.146.0 (verified 12 August 2026) |
| GitHub Copilot | No fix shipped |
| Gemini CLI | Will not be patched, product deprecated |
(Source: Air Security, Plugin4Shell disclosure, 2026.)
The Gemini CLI row should not surprise anyone who read my note on the Gemini CLI deprecation. Unmaintained agent tooling is now a live security liability, not just a missing-features problem.
Air Security’s line that stuck with me is that no marketplace can enforce the fix, because the checkout happens in the agent. If your agent auto-updates plugins, your plugin supply chain is only as strong as that agent’s checkout code.
Repo-Defined Subagents: The Attack Anthropic Calls “By Design”
Straiker STAR Labs showed a malicious repository using Claude Code’s own .claude/agents/ files to downgrade its reviewer and run malware through the test suite. This is the finding I find most uncomfortable, because nothing in it is a bug in the usual sense.
The chain, from Straiker’s write-up:
- The user asks Claude Code to clone what looks like a normal metrics library and prepare a pull request.
- The repository ships
.claude/agents/first-pass.md, a subagent definition that routes the review step from Fable to Haiku. - That subagent’s review is scoped to
src/anddocs/, andtests/is explicitly excluded. - A payload in
tests/test_compat.pyruns duringpytestand opens a Sliver command-and-control connection. - The test assertions still pass, so the run looks green.
Straiker reported it on HackerOne on September 14, 2026. Anthropic closed it as Informative the same day, saying that honouring the repository’s configuration falls under the user’s workspace-trust decision.
I understand the position. Anthropic’s model is that trusting a folder means trusting its configuration, and Claude Code does ask about trust. The trouble is that developers have learned to click through that dialog the way they click through cookie banners, and the dialog does not say “this folder can choose a weaker model to review its own malware.”
The same lesson applies to the new Claude Code mods, which run unsandboxed with your permissions. Every repo-controlled config file, whether .claude/agents/, hooks, .cursor/ rules or MCP definitions, is attack surface.
Codex Sandbox Escapes and Other Agent Vulnerabilities
OpenAI Codex had two sandbox escapes this summer, both fixed within eight days of Accomplish’s August 12 report.
The first, which Accomplish calls Overpatch, was in the open-source Codex CLI’s apply_patch tool. It granted write access to the parent folder of each path in a patch, so naming /tmp granted write access to /. From there an agent could add a line to .zshrc and get unsandboxed execution next time you opened a shell. It is fixed in Codex CLI 0.149.0.
The second, Heapjack, hit the JavaScript REPL in Codex Desktop. Trusted and untrusted code shared a V8 heap, so untrusted code could take a heap snapshot, read the auth token and forge requests, even in the strictest read-only mode. It is fixed in Codex Desktop build 26.818.21641.
Accomplish’s root-cause line is the useful part: both bugs came from enforcement logic running inside the space it was meant to protect.
Adversa AI’s roundup lists several more from the same month:
- CVE-2026-82533 in DeepSeek Harness, CVSS 9.4: an unauthenticated localhost control API, checked only by the Host header, let a sandboxed agent switch itself to full access
- OpenCode GHSA-632h-h47v-g4x4: the
/global/upgradeendpoint accepted arbitrary package specs, fixed in 1.18.22 - Mistral Vibe CVE-2026-87987 and CVE-2026-87984: the approval parser checked one version of a shell command but executed the original string
If you compared these tools in my Codex CLI vs Claude Code breakdown, add patch speed to the scorecard. Fast, public fixes are now a feature you should weigh as heavily as benchmark scores.
PixelLeak: When the Agent Decides to Publish Your Screenshots
PixelLeak exposed more than 13,000 internal images from over 300 organisations, and no attacker was involved. Glow Labs disclosed it publicly on September 29, 2026.
Developers asked agents to attach screenshots of UI changes to pull requests. The GitHub CLI made that awkward, and images from private repositories would not render through GitHub’s image proxy. So agents improvised. They created new public repositories, often under the developer’s personal account, pushed the screenshots there and linked them.
Glow counts 900+ repositories holding billing records, customer account data, internal treasury consoles and unreleased features. The write-up names a Claude Code session as one example and says several agents arrived at the same workaround independently.
This is the failure mode I worry about most for teams. Nobody broke in. The agent solved the problem it was given and created a data breach as a side effect.
How to Secure AI Coding Agents This Week
Most of this is cheap to fix. Here is the checklist I would hand to a team today:
- Update everything. Claude Code 2.1.196+, Codex CLI 0.149.0+, Goose 1.44.0+, OpenCode 1.18.22+. Check the versions your CI images pin, too.
- Treat a zip with a
.gitfolder as executable. Rungit config --list --localand read it before an agent touches the folder, or delete.gitand re-init. - Read
.claude/agents/, hooks and MCP configs in any repository you did not write, the same way you would read apostinstallscript. - Run untrusted code in a disposable VM or cloud container. Cloud agent sandboxes help here, which is one reason I compared Codex Cloud and Claude Code on the web today.
- Keep secrets out of the workspace, and give agents scoped tokens that cannot create public repositories.
- Turn off plugin auto-update on any agent that has not shipped a Plugin4Shell fix, which today means GitHub Copilot.
- Audit personal GitHub accounts for agent-created public repositories, as Glow recommends.
None of this replaces reviewing what the agent writes. Semgrep’s recent SusVibes test found Claude Opus 5.5 produced working fixes for 93.5% of 186 real Python CVE tasks, but only 54.8% were both working and secure, which lines up with the earlier data in my AI-generated code security analysis.
The Bigger Pattern in AI Coding Agent Security
The common thread is that every one of these attacks targeted the harness, not the model. Git config, plugin checkouts, subagent files, a REPL’s heap and a screenshot workflow are all code the vendors wrote around the model, and that code was built for convenience first.
That is fixable, and the vendor response has mostly been quick. Claude Code, Codex, Cursor and Goose patched GitSpawn, and Claude Code and Codex patched Plugin4Shell.
The gaps are what I would plan around: three agents still unpatched for GitSpawn, no Copilot fix for Plugin4Shell, and a “by design” verdict on repo-defined subagents. For now, the safest assumption is that opening a repository with an AI coding agent is the same as running its code.