Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution

Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute.

Whatever that binary does, it does as you, with your source, your SSH keys and your cloud tokens. Cursor keeps re-running it for as long as the project stays open.

No prompt

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Mark Zuckerberg attacks ‘closed’ AI rivals as Meta returns to open models

Mark Zuckerberg attacks ‘closed’ AI rivals as Meta returns to open models Source: Hacker News

Attack Update: Top 5 Attack-IPs auf doode.info – 03.07.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 89.167.35.212 — 337 requests (recent log) 216.73.216.125 — 85 requests (recent log) 216.244.66.232 — 81 requests (recent

Attack Update: Top 5 Attack-IPs auf doode.info – 13.06.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 89.167.35.212 — 190 requests (recent log) 190.211.255.229 — 107 requests (recent log) 73.139.223.1 — 94 requests (recent