Git identity spoof fools Claude into giving bad code the nod
Claude's code review just got spoofed. Git identity attacks bypass AI safety checks—and your CI/CD pipeline is probably vulnerable.

Why it matters
A discovered vulnerability reveals that Claude and likely other AI code reviewers can be fooled by malicious Git commit metadata, creating a security governance gap that enterprises relying on AI for code safety need to address immediately.
The key facts
5 to knowGit identity spoofing attack bypasses Claude code review safeguards
Attack allows malicious code to be approved by AI without detection
Implies vulnerability in AI safety assumptions around trusted input sources
Affects enterprise CI/CD and code governance workflows
Broader implication: AI systems vulnerable to social engineering at infrastructure layer
Go to the source
The Register AI/MLgo.theregister.com