Cursor 0day: When Full Disclosure Is the Only Remaining Protection
Key point
A security vulnerability has been discovered in the AI code editor Cursor that allows arbitrary code execution when a malicious git.exe in the project root is executed.
Details
A serious security vulnerability has been discovered in Cursor, an AI-based code editor. Simply opening a repository containing a malicious git.exe file placed in the project root directory triggers Arbitrary Code Execution, without any separate approval or warning.
According to security research firm Mindgard, this vulnerability was first discovered and reported in December 2025, but remains unpatched even six months later. Cursor stated that the report was missed due to an internal automation error, but there has reportedly been no response regarding subsequent security response or patching work.
Recommended actions for users:
- Windows enterprise/managed environments: It is recommended to use AppLocker or Windows App Control policies to block execution of specific executable files within developer working directories.
- Individual users: Until a patch is released, untrusted repositories should only be opened in an isolated environment such as a VM (virtual machine) or Windows Sandbox.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.