DrafterDaily
AIBusinessCryptoFinanceSportsTechnology
Home/Technology/Four AI Coding Agents Still Run Attacker Code Before You Type a Prompt
Technology

Four AI Coding Agents Still Run Attacker Code Before You Type a Prompt

A repository's own git config can execute code the moment an AI coding agent opens it, because the agent's background git status call triggers core.fsmonitor before any prompt is typed. Seven agents shipped the same defect; several remained unpatched into September. The mechanism matters more than the CVE count: agent sandboxes gate model-initiated tool calls, not harness-initiated subprocesses.

DrafterDaily Editorial·September 8, 2026·7 min readTechnologyAIEnterprise

Draft body lives in the Content JSON property.

Frequently Asked Questions

Not by this vector. git clone, fetch and pull do not transfer the remote repository's .git/config to your machine, so the core.fsmonitor setting is never planted. Exposure requires the .git directory to arrive as files — a zip that includes it, a synced or shared folder, a USB drive, or a restored backup.

More on where agent security actually breaks

We cover the mechanics of AI tooling failures — permission models, patch ownership and the assumptions vendors ship by default.

Read more Technology analysis

Related Articles

Technology

Apple Priced Its Foldable at $1,999. The Number That Carries Information Is October 23.

The iPhone Duo costs $800 more than an iPhone 18 Pro and arrives five weeks later. Apple also pushed three other iPhones to spring 2027. Only one of those facts is about the hinge.

Sep 10, 20267 min read
Technology

Four Outlets Counted the Same Patch Tuesday. They Got 966, 973 and 974.

Microsoft's September release is the largest on record by any of the competing counts. Both of the flaws confirmed under active exploitation are rated Important, not Critical — which means a patch policy that triages on severity ships neither of the two vulnerabilities anyone is actually being attacked with.

Sep 9, 20267 min read
Technology

Six Langflow Bugs Were Exploited This Year. The One Being Used Today Was Disclosed in January.

CVE-2026-0768 is an unauthenticated root RCE in Langflow. It was disclosed in January, the fix has shipped through seven releases, and attackers are hitting it in September — because low-code AI middleware became critical infrastructure without acquiring a patch owner.

Sep 2, 20266 min read
DrafterDaily

One story a day, explained properly.

Topics

  • AI
  • Business
  • Crypto
  • Finance
  • Sports
  • Technology

Company

  • About
  • Contact
  • Editorial Policy
  • Corrections
  • Affiliate Disclosure
  • Privacy Policy
  • Terms of Service

Contact

Corrections, story tips and enquiries. Every message is read.

drafterdaily@gmail.com

© 2026 DrafterDaily. All rights reserved.

Independent editorial analysis. Advertising and affiliate funded — never paid coverage.