The Point: Cursor automatically executes git.exe from the project directory, enabling code execution with user privileges and access to sensitive credentials.
Cursor on Windows automatically loads and executes a file named git.exe from the project directory when a cloned repository is opened, without confirmation or warning. The execution occurs with the user’s permissions and has access to SSH keys and cloud tokens.
Cursor, the popular IDE extension on Windows systems, contains a critical security vulnerability: as soon as a project is opened, the application checks the project directory for a file named git.exe and automatically executes it – without user input, without permission dialog, without warning.
The executed binary file runs with the privileges of the current user and has full access to SSH keys, cloud tokens, and the project’s source code. As long as the project remains open in Cursor, the file is continuously re-executed. This allows attackers to provide malicious repositories with a manipulated git.exe and execute arbitrary code when a developer clones the project and opens it in Cursor.
This execution mechanism poses a significant security risk for development teams, particularly when working with repositories of unknown origin or in supply-chain scenarios. Affected parties should check whether Cursor is deployed in their infrastructure and consider implementing security measures that restrict opening unknown repositories without additional validation.
Source: thehackernews.com · Published 15 July 2026
Lumi AI News — AI-assisted curation according to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.