- Sources: Mindgard write-up, HN 48910676
- Summary: Mindgard published a full-disclosure write-up on 2026-07-14 for an unpatched arbitrary-code-execution flaw in the Cursor editor on Windows. When Cursor opens a project it searches for a Git binary across several locations including the workspace root, so a malicious
git.exe placed in a repository root runs automatically with the user's privileges, without any prompt, and repeats on a cadence during normal editing. The root cause is the Windows executable-search behavior that resolves the current directory before system paths. The researcher reported it to Cursor on 2025-12-15 and through HackerOne on 2026-01-15, HackerOne confirmed delivery on 2026-01-20, and the flaw was still present through version 3.2.16 as verified on 2026-04-30 with no substantive vendor response. No CVE has been assigned. - Comments: HN commenters split on scope. Some read it as the long-known Windows current-directory search-order quirk that affects any IDE calling an unqualified binary name, comparable to a poisoned dotfile, while others note that agents with permission to clone repositories could pull a malicious repo autonomously and trigger mass exploitation.
- Why it matters: A widely used AI editor runs an attacker-controlled binary on project open with no confirmation, and the only stated mitigations are OS-level allow-listing or opening untrusted repositories in a disposable VM.
- Follow-up: Watch for a Cursor patch that restricts Git-binary resolution to trusted paths, a CVE assignment, and any exploitation reports.
send feedback on this story