hacker-news · Crawled Jul 15, 2026

Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution

1 IoCs 1 CVEs
Read original article ↗

AI Summary

A critical vulnerability in the Cursor IDE on Windows allows malicious cloned repositories to trigger arbitrary code execution by placing a file named git.exe in the project root. When the repository is opened, Cursor automatically executes this binary without user consent, enabling attackers to run code with the user's privileges, including access to SSH keys and cloud tokens. Despite being reported in December 2025, no patch has been released, and the issue remains unaddressed in the latest version. Similar behavior has been observed in other AI-powered development tools, indicating a broader trend in untrusted search path vulnerabilities.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 1 extracted

Type Value Detail
Filename git.exe Details →

MITRE ATT&CK TTPs 2 techniques