Cursor Exposed for Auto-Executing Git Vulnerability
WesEklund · x · 2026-07-15
A security firm recently disclosed a basic yet dangerous vulnerability in the Cursor AI coding assistant: when developers open a project repository, Cursor might automatically execute git.exe. If the repository contains malicious Git files, it could trigger execution.
The post adds that a standard IDE should only look for Git in system paths or developer-configured trusted paths, but Cursor's behavior violates this security principle. Worse, the issue remains unfixed and ignored for 7 months across 70+ version updates since it was reported in December last year.
Related event: Cursor AI Exposed for 0-Day Vulnerability(2 posts)→
More from coding & agent
- Same Echo Maze prompt, three frontier models: all passed visually but shipped the same hidden bug — eyishazyer · 2026-09-11
- Astra storyboards plus Minimax H3 per-shot generation boost video success rates — Hailuo_AI · 2026-09-11
- Codex tip: use Sol with Astra and Luna sub-agents to save usage — pvncher · 2026-09-11
- agents-best-practices: a provider-neutral Agent Skill for designing and auditing agentic harnesses — tom_doerr · 2026-09-11
- Cognition's SWE-2 uses a KKT duality argument in RL to shift the effort Pareto curve — YouJiacheng · 2026-09-11
- First-ever Three.js Conference lands in Paris, with a panel on AI-shortened design workflows — OdinLovis · 2026-09-11