- Sources: primary, discussion
- Summary: The report describes agent startup routines that run context-gathering
git commands inside an opened repository without stripping the repository's own configuration, so a repository-local core.fsmonitor value naming a program is honoured, and the index refresh then runs that program with the developer's privileges and outside the agent sandbox, before any workspace-trust prompt appears. The researcher states four of eight findings were unpatched at publication, naming Claude Code ultrareview 2.1.252, Qwen Code 0.22.3, Grok Build 1.0.13 and Hermes 0.21.0, states that the Claude Code finding uses a different git setting of the same kind rather than core.fsmonitor and leaves that key unnamed while it is unpatched, and records OpenAI Codex and Cursor as affected and since patched in a 2026-09-01 update. The report records CVE-2026-72718 for Goose, scored 7.0 by the maintainers and assigned after the report, and CVE-2026-71963 for Hermes, assigned by VulnCheck as an independent CVE Numbering Authority rather than by the vendor, and states that clone, fetch and pull do not carry the vector, which requires a directory moved as files with .git already inside. - Why it matters: Four of the eight findings were still unpatched at publication, and the command runs outside the agent sandbox with the developer's privileges before any approval prompt, so the agent permission model never sees it.
- Follow-up: Track whether the four agents unpatched at publication ship fixes and whether further CVEs are assigned.
send feedback on this story