Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Cursor AI's Silence on a Critical Flaw Jeopardizes Millions of Users

Дата публикации: 15-07-2026 09:59:20

The flaw lets any repository auto-execute code on Cursor for Windows, and researchers say the company ignored it.

Основное содержимое страницы с новостью.

Warp Terminal

Mindgard just disclosed an unpatched 0-day in Cursor yesterday, where a poisoned repository could trigger arbitrary code on Windows systems without the developer needing to do anything on their end.

The bug lives in how Cursor resolves Git binaries when a project loads. Cursor checks several locations for git, and one of them is the workspace itself.

Plant a file called git.exe at the root of a repository, and Cursor runs it the moment that project opens. This happens because the execution is integrated into the normal startup routine, something you'd probably never notice unless you went looking for it.

Mindgard proved this by renaming the Windows Calculator app to git.exe and placing it in a test repo. Opening that repo in Cursor launched it instantly, with the flaw repeatedly spawning new instances of the app.

on a windows system, the task manager is shown on the left with many processes visible, on the right are numerous instances of the calculator app being launched by cursor due to a critical flawHere you can see many instances of the Calculator app being launched by Cursor repeatedly.

This is not something Cursor didn't know about. Mindgard's Aaron Portnoy first reported the bug on December 15, 2025, then followed up repeatedly in the months after.

Getting anyone to respond took a public LinkedIn post asking for a security contact. Cursor's CISO eventually replied privately, blaming a broken automation for the missed HackerOne invite.

The stonewalling didn't stop there, as the bug report on HackerOne was closed prematurely, being termed "informative and out of scope." Mindgard pushed back, HackerOne reopened it, and confirmed the details had reached Cursor.

Days passed, and the silence from Cursor was more apparent. Requests for updates in February, March, and April were left unanswered, all while they were busy shipping new releases.

Five months of cat and mouse, and Mindgard finally decided to go public.

There's a responsethe about dialog of the linux client for cursor is visible in the foreground, the background has the rest of the cursor interface with a wall of codeJust a placeholder image of Cursor's Linux build.

Albeit a very vague one. Speaking to Dark Reading, an unnamed spokesperson for Cursor informed them that:

I can confirm we are addressing this and will get back to Mindgard accordingly.

That statement isn't very confidence-instilling for an issue that feels magnitudes higher.

But what do I know about handling sensitive cybersecurity issues in a big AI firm? Maybe they had good reason to ignore the issue and were working on some shiny new AI feature. 🤷


Suggested Read 📖: Did you know a storage bug on Windows 11 could eat up disk space?

Enjoyed this update? Support independent Linux news coverage

It's FOSS has been helping people use Linux for the past 14 years. Help us stay independent from big tech. Become a Plus member, enjoy ad-free reading and get 5 eBooks.

Best value

Plus lifetime

Pay once, Enjoy forever

Go lifetime

About the author

Sourav Rudra
Sourav Rudra

A nerd with a passion for open source software, custom PC builds, motorsports, and exploring the endless possibilities of this world.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Атакована недоисправленная уязвимость в Windows-2609-07-2026
2 Malicious GitHub Repositories Could Trick AI Coding Agents Into Running Hidden Malware, Researchers Warn 0728-06-2026
3Microsoft’s open source tools were hacked to steal passwords of AI developers-2608-06-2026
4Malicious AI Coding Plugins Hit JetBrains Marketplace, Stealing API Keys From Developers-2817-06-2026
5В Windows сломалась важная функция-5314-07-2026
6Malicious Hugging Face Models Could Trigger Remote Code Execution-2605-06-2026
7'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets-2711-07-2026
8 Microsoft acknowledges a Windows 11 bug affecting the Recycle Bin, and 'fed up' users think AI coding is to blame 0521-06-2026
9В чипсетах Intel обнаружили неустранимую уязвимость0005-03-2020

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 9. Тональность: -5. Информативность: 7. Источник: itsfoss.com.