Article may be outdated

This article is 84 days old. Some details may have changed since publication.

Hacker News·4 min read·medium

Cursor 0day: When Full Disclosure Becomes the Only Protection Left

S
Synthetic7346
Cursor 0day: When Full Disclosure Becomes the Only Protection Left
✦AI Summary

A critical security vulnerability in the Cursor AI-assisted IDE allows for arbitrary code execution when a user opens a repository containing a malicious git.exe file. Despite being reported by security researchers at Mindgard over six months ago, the issue remains unpatched and the company has largely ceased communication regarding the flaw.

Why it matters

As Cursor is a widely used development tool, this unpatched vulnerability poses a significant supply chain risk to tens of thousands of companies and millions of developers who may unknowingly execute malicious code simply by opening a project.

✦Dive DeeperCreate a free account to unlock

Discover shadow AI and agents. Reveal the AI attack surface

Continuously test AI agents & systems against evolving attacks

Find and fix AI security and safety vulnerabilities

Identify and respond to attacks in real time

The vulnerability nobody seems interested in fixing

After loading a project, Cursor attempts to find git binaries at various locations including the current workspace. By creating a repository with a planted malicious git.exe in the root, the IDE will execute it with no user interaction and no prompting of the user. This occurs repeatedly on a cadence.

Sometimes security research uncovers deeply technical vulnerabilities that require pages of explanation. This isn't one of those cases.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologybusiness
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in