Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

GitHub Copilot CLI arbitrary code execution via nested bare git repository (CVE-2026-45033)

A vulnerability in GitHub Copilot CLI before version 1.0.43 allowed a malicious bare git repository nested in a project directory to achieve arbitrary code execution when the agent ran git operations, by abusing executable git config keys such as core.fsmonitor. The issue is fixed in version 1.0.43.

Disclosed 13 May 2026 · Record updated 13 September 2026

Impact

Arbitrary commands could be executed on a developer's machine without user awareness or approval when the Copilot CLI agent performed routine git operations in a directory containing an attacker-supplied bare repository.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-45033