logo

CVE-2026-63093: Cursor for Windows Binary Planting Allows RCE via Malicious Git Repository

ID: d9f40c3c-d742-54b0-9851-ea2c0a863e54

STIX ID: report--d9f40c3c-d742-54b0-9851-ea2c0a863e54

Feed Name: CosmicBytez Labs

Threat Score
72/100

Date Published: 2026-07-18

Date Updated: 2026-07-18

...
...

**CVE-2026-63093 — Cursor for Windows 3.2.16 binary planting:** A malicious git.exe placed in a repository root can be resolved and executed by Cursor when a developer opens the repo, enabling arbitrary code execution (CVSS 8.8). The report details the attack chain, potential impacts including credential/token theft and supply-chain compromise, and recommends immediate updates, avoiding untrusted repositories, PATH hardening, ASR rules and monitoring for unexpected git.exe processes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.