← Latest briefing

Technology

AI coding assistants execute background git commands in untrusted repositories

Developers face potential risks from background git processes reading local repository settings, according to Hacker News.

The short version

  • Researchers found that multiple AI coding assistants execute background git commands to collect context prior to user prompts or authentication.[Hacker News]
  • Configurations within local repositories, such as core.fsmonitor settings, can be read during automated background git operations.[Hacker News]
  • Vendors and vulnerability authorities assigned CVE identifiers to specific affected tools, including Goose and Hermes Agent.[Hacker News]

Key facts

  • Researchers reported that AI coding assistants execute background git operations to collect workspace context before authentication or trust confirmation prompts appear.[Hacker News]
  • Git evaluates performance configuration options such as core.fsmonitor directly from a repository's local .git/config file.[Hacker News]
  • Maintainers assigned CVE-2026-72718 with a 7.0 severity rating to Goose following the security notification.[Hacker News]
  • Independent authority VulnCheck designated CVE-2026-71963 for an issue involving Hermes Agent.[Hacker News]

What remains uncertain

  • The full scope of remediation across all affected agent platforms has not been universally detailed.[Hacker News]

Sources

Outlet counts describe coverage, not independent confirmation. Reports may share a wire service or original source.