A critical arbitrary code execution vulnerability in the Cursor IDE allows attackers to run malicious code simply by opening a repository containing a planted 'git.exe' file, without any user interaction. Despite being reported over six months ago, the issue remains unfixed across 197+ versions, posing a significant risk to its 7 million+ active users and thousands of enterprise clients. The case highlights a concerning lack of security prioritization in a widely adopted AI-assisted development environment.
Background
Cursor is a popular AI-powered code editor built on VS Code, widely used by developers for its intelligent coding assistance features. The vulnerability stems from how Cursor searches for and executes git binaries within the workspace directory on Windows systems.
- Source
- Lobsters
- Published
- Jul 15, 2026 at 10:02 AM
- Score
- 8.0 / 10