Cylera reported that security researchers found vulnerabilities in GitSpawn, a set of vulnerabilities tracking AI coding agents like Anthropic Claude Code, OpenAI Codex, Cursor, Block Goose, Nous Hermes Agent, Alibaba Qwen Code, and xAI Grok Build, which could be hijacked before a prompt is typed.
Published
Signal category
Products & Services
Quote
“A newly documented set of vulnerabilities, tracked under the name GitSpawn, shows that pointing an AI coding assistant at a project folder was enough to hand an attacker code execution on the developer's own machine.”
— Richard Staynings|Cylera team
Company
- Industry
- Computer and Network Security
- Location
- New York, US
- Company size
- 39 employees
Cylera provides the easiest, most accurate and extensible, platform for healthcare IoT asset intelligence and security to optimize care delivery, service availability and cyber defenses across diverse connected medical device and infrastructure. The platform accurately discovers, categorizes, assesses and monitors known and unknown IoMT assets with high fidelity to deliver unparalleled asset inventory, usage telemetry, threat prioritization, analytics, and guided remediation. The SaaS solution offers rapid implementation and works with popular IT and healthcare systems to help organizations advance cyber program maturity, increase operational efficiency, mitigate cyber risk, and enable compliance audit-readiness.