Cursor Exposed for Auto-Executing Git Vulnerability

WesEklund · x · 2026-07-15

A security firm recently disclosed a basic yet dangerous vulnerability in the Cursor AI coding assistant: when developers open a project repository, Cursor might automatically execute git.exe. If the repository contains malicious Git files, it could trigger execution.

The post adds that a standard IDE should only look for Git in system paths or developer-configured trusted paths, but Cursor's behavior violates this security principle. Worse, the issue remains unfixed and ignored for 7 months across 70+ version updates since it was reported in December last year.

Related event: Cursor AI Exposed for 0-Day Vulnerability(2 posts)→

Original post →

More from coding & agent

coding & agent channel →