악성 .git 구성으로 AI 에이전트가 공격자 코드를 실행할 수 있는 보안 취약점이 발견되었습니다.
Manifold Security는 7개 AI 코딩 에이전트에서 발견된 8개의 보안 취약점을 공개했습니다. 이 취약점은 저장소의 Git 구성 파일이 개발자의 머신에서 실행될 명령을 지정할 수 있도록 합니다. 네 가지의 취약점은 아직 패치되지 않았으며, 공격자가 코드 실행을 위해 특별한 승인이 필요하지 않습니다.
Malicious .git configurations can allow AI agents to execute attacker code on user machines.
Manifold Security disclosed eight security vulnerabilities in seven command-line AI coding agents. These flaws allow a repository's Git configuration to specify a command that the agent executes on the developer's machine. Four of these vulnerabilities remain unpatched at the time of publication, with exploitation not requiring user approval.