logo

Cursor IDE Auto-Executes Malicious Code in Poisoned Repos

ID: 99aa66ca-89d1-53b8-b8f0-bc392e401d65

STIX ID: report--99aa66ca-89d1-53b8-b8f0-bc392e401d65

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-07-14

Date Updated: 2026-07-15

Author: Alexander Culafi

...
...

Mindgard disclosed a critical flaw in the Cursor AI development client where Cursor searches for Git binaries including within the workspace; an attacker can plant a malicious git.exe in a repository root which Cursor will automatically execute when the project is opened, allowing arbitrary code execution under the developer's privileges. Mindgard reported the issue to Cursor months earlier with no fix, published a PoC (renaming Calculator to git.exe) and recommends mitigations such as AppLocker or opening untrusted repos only in isolated environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.