Claude Code Patched GitSpawn Startup Flaw in Version 2.1.196
Key point
The vulnerability allowed a transferred folder with .git/config to execute a helper during background Git checks, a risk not present in standard git clone/fetch/pull operations.
Details
Claude Code addressed a startup vulnerability identified by Manifold Security, where a transferred folder containing .git/config could trigger the execution of a helper during background Git checks. This flaw, termed GitSpawn in the source title, highlighted the security risks associated with background setup processes that differ from standard user-initiated commands.
Security Implications
The core issue lay in the distinction between background operations and interactive commands. While ordinary git clone, fetch, and pull commands do not carry local configuration risks in the same manner, the specific startup path in Claude Code did. This underscores the need for rigorous scrutiny of background tasks in AI coding assistants, as they may encounter risks not present in explicit user commands.
Resolution Status
The vulnerability was fixed in Claude Code version 2.1.196. The disclosure serves as a retrospective explanation of the patched flaw rather than an active threat, emphasizing that the issue is resolved in current releases.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.