hacker-news · Crawled Jul 15, 2026
Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution
1 IoCs 1 CVEs
Read original article ↗
AI Summary
A critical vulnerability in the Cursor IDE on Windows allows malicious cloned repositories to trigger arbitrary code execution by placing a file named git.exe in the project root. When the repository is opened, Cursor automatically executes this binary without user consent, enabling attackers to run code with the user's privileges, including access to SSH keys and cloud tokens. Despite being reported in December 2025, no patch has been released, and the issue remains unaddressed in the latest version. Similar behavior has been observed in other AI-powered development tools, indicating a broader trend in untrusted search path vulnerabilities.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | git.exe | Details → |