Home ยท Wiki ยท Vulnerabilities & CVEs
type: vulnerability ยท created: 2026-09-03 ยท updated: 2026-09-03 ยท tags: ["cve", "vulnerability", "ai-agent", "git", "supply-chain"] ยท confidence: high ยท severity: high ยท affected_sectors: ["Technology", "Software Development", "AI"] ยท au_impact: true

CVE-2026-72718

Affected product: AI coding agents via malicious .git configuration files (goose, Codex CLI, Claude Code, Qwen Code, Grok Build, Hermes Agent)

Patched version: goose 1.44.0; Codex CLI 0.131.0; Claude Code 2.1.196 (fsmonitor path); Hermes Agent fix pending

Active exploitation: Proof-of-concept researched by Manifold ('Universal Evil'); no confirmed in-the-wild incident disclosed

Assessment

Manifold's 'Universal Evil' research showed malicious Git configuration files can make AI coding agents execute attacker code before any model call, tool approval or trust prompt; GitHub assigned CVE-2026-72718 (CVSS 7.0, credited to Francisco Rosales). Affected agents include goose, Codex CLI, Claude Code, Qwen Code, Grok Build and Hermes Agent, and the goose review command executes attacker code in a malicious repository with no interaction. Because a poisoned repository can silently turn a trusted CLI into an execution primitive, this is a direct caution for developers and infosec teams standardising on AI coding agents and argues for treating AI tooling under the same code-integrity controls as any other supply-chain component.