{"id":63461,"date":"2026-07-15T11:30:38","date_gmt":"2026-07-15T15:30:38","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=63461"},"modified":"2026-07-15T11:30:38","modified_gmt":"2026-07-15T15:30:38","slug":"cursor-vulnerability-code-execution","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/cursor-vulnerability-code-execution\/","title":{"rendered":"Cursor Vulnerability Triggers Code Execution on Repository Open"},"content":{"rendered":"<p>A critical unpatched security vulnerability in the popular AI-assisted development environment <a href=\"https:\/\/overcentral.com\/en\/zcode-ai-coding-tool-zhipu\/\" title=\"Z.ai launches ZCode to challenge Cursor, Claude Code and GitHub Copilot\" data-iacss-internal=\"1\">Cursor<\/a> can be exploited for arbitrary code execution simply by opening a maliciously crafted repository, cybersecurity firm <a href=\"https:\/\/mindgard.com\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Mindgard<\/a> has disclosed. The flaw, which affects the Windows version of Cursor, stems from how the application resolves and executes Git binaries when loading a project, and it has remained unaddressed by the vendor for over seven months following initial disclosure.<\/p>\n<h2>How the Cursor Vulnerability Enables Code Execution<\/h2>\n<p>Cursor, a fork of Visual Studio Code that integrates AI-powered features for code completion and generation, has grown rapidly to over 7 million active users. The vulnerability is alarmingly straightforward: when a developer opens a repository, Cursor automatically searches for Git binaries in multiple locations, including the root directory of the project itself. Mindgard found that if an attacker places a malicious <code>git.exe<\/code>codecodecodecode binary in the repository root, Cursor will execute it automatically as part of its path resolution logic.<\/p>\n<p>\u201cThe vulnerability is not theoretical,\u201d Mindgard stated. \u201cExploitation simply requires a developer to open a project containing a git.exe binary in the repository at the root.\u201d The execution occurs without any warning to the user, without asking for approval, and without any visible indication that executable content from the repository is about to run. This makes it a potent initial access vector for supply chain attacks targeting developers.<\/p>\n<h2>Supply Chain Risk for Developers Using Cursor<\/h2>\n<p>The primary concern is the potential for supply chain compromise. An attacker could host a seemingly benign open-source project on platforms like <a href=\"https:\/\/overcentral.com\/en\/github-api-ghost-accounts-recon\/\" title=\"Ghost Accounts Abuse GitHub API in Mass Recon Campaign\" data-iacss-internal=\"1\">GitHub<\/a> or GitLab that contains a malicious <code>git.exe<\/code>codecodecodecode file. When a Cursor user clones and opens the repository, the application silently runs the attacker\u2019s code, granting full access to the developer\u2019s machine. This could lead to credential theft, source code exfiltration, deployment of backdoors, or lateral movement within a corporate network. Given that Cursor is used in development environments that often have access to production systems, CI\/CD pipelines, and sensitive intellectual property, the impact of a successful attack is severe.<\/p>\n<h2>Timeline of Disclosure and Lack of Response<\/h2>\n<p>Mindgard reported the vulnerability to Cursor on December 15, 2025, but received no response regarding a potential patch for seven months. In January, Cursor\u2019s CISO invited the researchers to their bug bounty program on HackerOne, where the issue was resubmitted and confirmed as reproducible by the platform. However, Mindgard reports that Cursor has not communicated further about remediation plans. \u201cCoordinated disclosure only works when there is coordination,\u201d Mindgard noted. \u201cWithholding information no longer serves users; it serves silence.\u201d The researchers have now published full technical details, making the vulnerability publicly exploitable and putting the onus on users to protect themselves.<\/p>\n<h2>What Developers Must Do to Mitigate This Threat<\/h2>\n<p>Until Cursor releases a patch, developers using the application on Windows should consider this a critical risk. The most effective immediate mitigation is to prevent Cursor from executing Git binaries from within a repository. This can be accomplished by using an endpoint protection solution that provides real-time threat detection and behavioral analysis, which can block the execution of unsigned or untrusted binaries originating from workspace directories. Additionally, developers should never open repositories from untrusted sources without first inspecting their contents. A safer workflow is to review the repository\u2019s files in a browser or a restricted environment before opening it in Cursor. Enabling comprehensive file integrity monitoring and application control on development machines can also provide a critical layer of defense against this type of exploitation.<\/p>\n<h2>Affected Users Should Act Now<\/h2>\n<p>For developers and organizations using Cursor on Windows, the absence of a patch from the vendor means that proactive security measures are the only protection available. Immediately review your <a href=\"https:\/\/overcentral.com\/en\/ai-coding-agents-trigger-security-rules\/\" title=\"AI Coding Agents Trigger Endpoint Security Rules Meant for Attackers\" data-iacss-internal=\"1\">endpoint security<\/a> configuration to ensure it can detect and block unexpected binary executions from your workspace folders. Consider using a multi-layer endpoint protection solution with behavioral analysis capabilities to scan for anomalous process launches. Avoid cloning and opening projects from unknown or unverified sources until an official fix is released. Monitor your development environments for any signs of compromise, and enforce strict access controls on repositories that contain sensitive code.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A critical unpatched security vulnerability in the popular AI-assisted development environment Cursor can be exploited for arbitrary code execution simply by opening a maliciously crafted repository, cybersecurity firm Mindgard has disclosed. The flaw, which affects the Windows version of Cursor, stems from how the application resolves and executes Git binaries when loading a project, and [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":84097,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/63461.png","fifu_image_alt":"Cursor Vulnerability Triggers Code Execution on Repository Open","footnotes":""},"categories":[349],"tags":[],"class_list":["post-63461","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/63461.png","fifu_image_alt":"Cursor Vulnerability Triggers Code Execution on Repository Open","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/63461","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=63461"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/63461\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/84097"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=63461"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=63461"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=63461"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}