Cursor Exposed for Auto-Executing Git Vulnerability
WesEklund · x · 2026-07-15
A security firm recently disclosed a basic yet dangerous vulnerability in the **Cursor AI coding assistant**: when developers open a project repository, Cursor might automatically execute `git.exe`. If the repository contains malicious Git files, it could trigger execution. The post adds that a standard IDE should only look for Git in system paths or developer-configured trusted paths, but Cursor's behavior violates this security principle. Worse, the issue remains unfixed and ignored for 7 months across 70+ version updates since it was reported in December last year.
Related event: Cursor AI Exposed for 0-Day Vulnerability(2 posts)→
More from coding & agent
- The author says Codex reached 20x and is now debugging spec decoding on a hybrid parallel setup — TheZachMueller · 2026-07-21
- Axcess adds an MCP connector for WCAG accessibility checks that scanners miss — modelcontextprotocol · 2026-07-21
- X post asks whether Cursor Composer, built on Kimi models, would also be banned — max_paperclips · 2026-07-21
- A developer’s Codex usage is draining pooled enterprise credits at a small company — Distinct_Relation_62 · 2026-07-21
- Qwen Code ships cua-driver-rs 0.7.3 with relative coordinates and MCP filtering — github-actions[bot] · 2026-07-21
- Matt Pocock says every new codebase turns legacy within days — mattpocockuk · 2026-07-21