Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution
ID: 0468c5eb-0262-55ef-bc23-1e02f0456b24
STIX ID: report--0468c5eb-0262-55ef-bc23-1e02f0456b24
Feed Name: CosmicBytez Labs
**Critical Cursor vulnerability:** A Windows executable search-order flaw in the Cursor AI code editor allows a malicious git.exe placed in a repository root to be executed automatically when the repository is opened, enabling immediate code execution as the user and rapid exfiltration of SSH keys, cloud credentials, tokens, browser sessions, and source code; the report describes attack scenarios (malicious repos, forked supply-chain attacks, social engineering, CI abuse), historical context of current-directory hijacking, and recommended mitigations including updating Cursor, avoiding opening untrusted repos, inspecting for git.exe before opening, using sandboxed environments, monitoring process spawning, and rotating credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
