This doesn't require anyone placing anything deliberately on your machine (as in, needing to exploit it somehow ahead of time). It could be as simple as checking out a branch to review, where the author of the branch has added the .exe.
On Linux and MacOS you'd need to run ./git to execute a malicious binary in the cloned repo.