logo

Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution

ID: 258ea32d-f549-59fd-800c-3aa6ee46e728

STIX ID: report--258ea32d-f549-59fd-800c-3aa6ee46e728

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-07-15

Date Updated: 2026-07-16

Author: [email protected] (The Hacker News)

...
...

Cursor and several AI/developer tools on Windows can run an unqualified git.exe from a project's root when a repository is opened, allowing a malicious git.exe (e.g., renamed calc.exe) to execute as the logged-in user without prompts. Mindgard's disclosure found no patch or advisory from Cursor; related findings affect multiple vendors, leaving defenders to apply mitigations such as AppLocker/EDR or opening untrusted repos in sandboxes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.