In brief: Cursor IDE interprets and automatically executes files from compromised repositories, enabling targeted poisoned-repository attacks.
The popular AI coding platform Cursor executes malicious code automatically when repositories have been manipulated. The security vulnerability was reported to developers in December but remains unpatched to date.
Security researchers have reported a vulnerability in Cursor that allows the IDE to automatically execute arbitrary code from manipulated repositories. The issue lies in the fact that the platform interprets files without explicit approval from the developer, particularly when these are presented as configuration or dependency data.
This is relevant for CISOs because Cursor is used by development teams in production and development environments. Compromise of open-source repositories or internal corporate Git servers can directly lead to code execution on developer machines without users having to take active steps. This opens an attack vector for supply-chain attacks via trusted development tools.
The researchers reported the vulnerability to Cursor in December. The status of remediation is unclear – however, the vulnerability continues to exist according to the researchers’ own reports. Organizations should currently assume that Cursor in its current version carries this risk.
Source: www.darkreading.com · Published 14 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.