Severe Execution Vulnerability Exposed in Cursor

nptacek · x · 2026-07-17

A recent post highlights a severe, seven-month unpatched vulnerability in Cursor: simply browsing a project triggers the automatic execution of git.exe located in the project's root directory.

This means that if a project maintainer's account is compromised and they upload a malicious executable, anyone using Cursor to browse the repository could be compromised as well, creating a massive attack surface.

Original post →

More from coding & agent

coding & agent channel →