Skip to content
Cursor IDE 0

Cursor IDE 0

Kucoin July 14, 2026

ME News reports that on July 15 (UTC+8), security firm Mindgard discovered a critical 0day vulnerability in Cursor IDE on December 15, 2025. When a user opens a repository containing a malicious `git.exe` on Windows, Cursor automatically executes the file without any user interaction. The vulnerability arises because Cursor searches for Git binaries in multiple locations, including the workspace, when loading a project. Mindgard reported the issue multiple times over seven months; although Cursor’s CISO acknowledged it, internal automation failures disrupted the remediation process, and over 70 new versions have been released without a fix. Temporary mitigations include using AppLocker to block execution of files with this name from workspace directories, or opening untrusted repositories in an isolated virtual machine. 🔗 Read the original: via AI HOT · (Source: AiHot)

Extracted Entities