CVE-2026-63093: Cursor for Windows Binary Planting Allows RCE via Malicious Git Repository
ID: d9f40c3c-d742-54b0-9851-ea2c0a863e54
STIX ID: report--d9f40c3c-d742-54b0-9851-ea2c0a863e54
Feed Name: CosmicBytez Labs
**CVE-2026-63093 — Cursor for Windows 3.2.16 binary planting:** A malicious git.exe placed in a repository root can be resolved and executed by Cursor when a developer opens the repo, enabling arbitrary code execution (CVSS 8.8). The report details the attack chain, potential impacts including credential/token theft and supply-chain compromise, and recommends immediate updates, avoiding untrusted repositories, PATH hardening, ASR rules and monitoring for unexpected git.exe processes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
