Cursor Exposed for Auto-Executing Git Vulnerability

WesEklund · x · 2026-07-15

A security firm recently disclosed a basic yet dangerous vulnerability in the **Cursor AI coding assistant**: when developers open a project repository, Cursor might automatically execute `git.exe`. If the repository contains malicious Git files, it could trigger execution. The post adds that a standard IDE should only look for Git in system paths or developer-configured trusted paths, but Cursor's behavior violates this security principle. Worse, the issue remains unfixed and ignored for 7 months across 70+ version updates since it was reported in December last year.

Related event: Cursor AI Exposed for 0-Day Vulnerability(2 posts)→

Original post →

More from coding & agent

coding & agent channel →