Code injections through Git commit messages
18 points by cve
18 points by cve
In-band signalling is always a mistake. Always has been. It was a mistake back when unix decided everything was a file, and it's a mistake now with LLM agent contexts.
Why does git pass the commit message to patch?