AISLE discloses 1-click RCE in Cursor, VS Code, and Google Antigravity, all now patched
stanislavfort · x · 2026-09-08
AISLE's AI vulnerability analyzer discovered a one-click remote command execution (RCE) vulnerability in Cursor, VS Code, and Google Antigravity—tools used by 50 million engineers. All three platforms have since been patched.
- The attack: malicious commands hidden in links inside commit messages; clicking one executed arbitrary code with full terminal privileges—no warning, no confirmation, no visible trace
- Impact: exfiltration of API keys and certificates (OpenAI, Anthropic, Stripe), persistent keyloggers broadcasting terminal input to external servers, file deletion
Disclosure timeline: found in VS Code and Cursor in Sep 2025 (Cursor fixed immediately); resurfaced in Google Antigravity after its Jan 2026 launch, fixed by Google within days; Microsoft later patched upstream VS Code. Full technical write-up on the AISLE blog.
More from coding & agent
- Indent launches shared company-wide AI agent that debugs, fixes and opens PRs from Slack — Scobleizer · 2026-09-09
- Codex can generate tool-calling code on the fly — a new failure point for agent devs — srchvrs · 2026-09-09
- Paper: general coding agents beat purpose-built data agents by up to 37 points — RishiBommasani · 2026-09-09
- astra-chess: open-source Codex + skills setup for playing chess with GPT-6 Astra — MikePFrank · 2026-09-09
- Weaviate shows how to turn a messy creative archive into semantic search without renaming files — philipvollet · 2026-09-09
- Factory Worker 'Raises' a Local Gemma 31b AI in a Folder — She Gave Herself a Sense of Touch — D33lix · 2026-09-09