In a nutshell: An unpatched vulnerability in Cursor enables attackers to execute arbitrary malicious code when a developer opens a prepared repository with a manipulated git.exe.
Security firm Mindgard has publicly disclosed an uncorrected vulnerability in the AI editor Cursor that enables arbitrary code execution on Windows systems. The flaw affects over seven million active users, despite being known for seven months.
Mindgard discovered a security vulnerability in the Windows version of the AI editor Cursor that allows attackers to automatically execute arbitrary malicious code without user notification. The problem lies in the editor’s search logic: when loading a project, Cursor searches multiple directories for Git installations, including the opened directory itself. If a file named git.exe exists in the root folder of a repository, Cursor executes it immediately upon startup – without a security prompt.
Mindgard reported the vulnerability to the Cursor developers on 15 December 2025 and presented it in January 2026 via the HackerOne bug bounty programme. After seven months without response or a planned update, the company decided to publicly disclose the vulnerability on 15 July 2026. The firm emphasises that exploiting the flaw requires no complex techniques such as prompt injections or model attacks – the mere presence of a manipulated git.exe in the repository root directory is sufficient.
Cursor confirmed the behaviour but classifies the vulnerability as outside the scope of the bug bounty programme. The company relies on a shared responsibility model whereby developers themselves decide which repositories, prompts and tools to use. Vulnerabilities that presuppose the presence of already manipulated files are not eligible for bounties.
As a countermeasure, Cursor recommends enabling the Workspace Trust feature, which opens untrusted folders in restricted mode and prevents automatic execution of malicious code repositories. Administrators can also enforce this setting across the network using mobile device management solutions.
Source: www.it-daily.net · Published 17 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.