6 points | by fourfire 2 days ago
2 comments
> Git reads that setting from the repository's own .git/config. So a repository can ship this:
Followed by:
> Delivery is worth being precise about, because git never carries this. Cloning a hostile URL does nothing, and neither does fetch or pull.
AI slop nothing burger. The “exploit” has nothing to do with coding agents.
GitSpawn: A Single Flaw Let's Untrusted Repos Run Code in Claude Code, Codex, Cursor, and Grok
> Git reads that setting from the repository's own .git/config. So a repository can ship this:
Followed by:
> Delivery is worth being precise about, because git never carries this. Cloning a hostile URL does nothing, and neither does fetch or pull.
AI slop nothing burger. The “exploit” has nothing to do with coding agents.
GitSpawn: A Single Flaw Let's Untrusted Repos Run Code in Claude Code, Codex, Cursor, and Grok