logo

Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay

ID: 2f0248e0-7e27-5748-9058-2492dd75c564

STIX ID: report--2f0248e0-7e27-5748-9058-2492dd75c564

Feed Name: TechRepublic Security

Threat Score
72/100

Date Published: 2026-07-28

Date Updated: 2026-07-28

Author: Joseph Ofonagoro

...
...

#### Executive summary: Mindgard disclosed a high-severity vulnerability (CVE-2026-63093, CVSS 8.8) in Cursor for Windows (3.2.16) where Cursor may execute a malicious git.exe placed in the root of a cloned repository, enabling attacker-controlled code execution with the user's privileges; Cursor patched the flaw after private disclosure and shortly before the public report, and the issue raises significant supply-chain and developer workstation compromise concerns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.