logo

Cursor 0-Day Flaw Executes Malicious git.exe From Repositories Without User Interaction

ID: aea02281-32da-550f-b4fb-16932e2bd561

STIX ID: report--aea02281-32da-550f-b4fb-16932e2bd561

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Divya

...
...

Research published in July 2026 details a zero-day vulnerability in the Cursor AI IDE for Windows that auto-executes a repository-root git.exe, allowing attackers to run arbitrary code with the user's privileges simply by opening an untrusted workspace; a benign proof-of-concept (renaming Calculator to git.exe) was shown, the issue was verified against Cursor 3.2.16, and mitigations (AppLocker, isolated VMs, sandboxing) are recommended until Cursor issues a patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.