CVE-2021-4389115.12.2021, 15:15Visual Studio Code Remote Code Execution VulnerabilityEnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTPrimary7.8 HIGHLOCALLOWNONECVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HBase ScoreCVSS 3.xEPSS ScorePercentile: 96.08%Affected Products (NVD)VendorProductVersionmicrosoftvisual_studio_code𝑥< 1.63.2𝑥= Vulnerable software versionsVulnerability Media Exposure[ENGLISH] Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker CodeManifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrivePublished: 2026-09-02T19:36:59+05:30Referenceshttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-43891https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-43891