Unpatched Cursor Vulnerability Exposes Users to Code Execution
An attacker can create a malicious repository containing a git.exe in the project root, and Cursor executes it automatically. The post Unpatched Cursor Vulnerability Exposes Users to Code Execution appeared first on SecurityWeek.
An unpatched vulnerability in Cursor on Windows can be triggered for code execution when a developer opens a repository in the application, Mindgard reports.
Cursor is one of the most popular AI-assisted development environments, with more than 7 million active users.
The security defect, Mindgard says, is straightforward: when opening a repository, Cursor would automatically execute a malicious git.exe binary in the project’s root without warning the user or asking for approval.
Source: https://www.securityweek.com/unpatched-cursor-vulnerability-exposes-users-to-code-execution/
Related breach coverage
- Zimbra Patches Critical Code Execution Vulnerability2026-07-13
The flaw results in malicious code embedded in crafted emails being executed when the emails are opened. The post Zimbra Patches Critical Code Execution Vulnerability appeared first on SecurityWeek.
- OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability2026-07-20
Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory. The post OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability appeared first on SecurityWeek.
- Fresh SharePoint Vulnerability Exploited Soon After Disclosure2026-07-17
The critical-severity security defect allows remote, authenticated attackers to execute arbitrary code on the server. The post Fresh SharePoint Vulnerability Exploited Soon After Disclosure appeared first on SecurityWeek.
- SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits2026-07-15
SonicWall SMA1000 zero-day vulnerabilities CVE-2026-15409 and CVE-2026-15410 can be exploited for remote code execution. The post SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits appeared first on SecurityWeek.
