Cursor 0day: When Full Disclosure Becomes the Only Protection Left

A critical security vulnerability in the Cursor AI-assisted IDE allows for arbitrary code execution when a user opens a repository containing a malicious git.exe file. Despite being reported by security researchers at Mindgard over six months ago, the issue remains unpatched and the company has largely ceased communication regarding the flaw.
Why it matters
As Cursor is a widely used development tool, this unpatched vulnerability poses a significant supply chain risk to tens of thousands of companies and millions of developers who may unknowingly execute malicious code simply by opening a project.
Discover shadow AI and agents. Reveal the AI attack surface
The report presents technical facts and a timeline of disclosure failures without using inflammatory language, focusing on the security implications and the lack of vendor response.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in