logo

Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution

ID: 0468c5eb-0262-55ef-bc23-1e02f0456b24

STIX ID: report--0468c5eb-0262-55ef-bc23-1e02f0456b24

Feed Name: CosmicBytez Labs

Threat Score
85/100

Date Published: 2026-07-15

Date Updated: 2026-07-16

...
...

**Critical Cursor vulnerability:** A Windows executable search-order flaw in the Cursor AI code editor allows a malicious git.exe placed in a repository root to be executed automatically when the repository is opened, enabling immediate code execution as the user and rapid exfiltration of SSH keys, cloud credentials, tokens, browser sessions, and source code; the report describes attack scenarios (malicious repos, forked supply-chain attacks, social engineering, CI abuse), historical context of current-directory hijacking, and recommended mitigations including updating Cursor, avoiding opening untrusted repos, inspecting for git.exe before opening, using sandboxed environments, monitoring process spawning, and rotating credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.