Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution

Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute.

Whatever that binary does, it does as you, with your source, your SSH keys and your cloud tokens. Cursor keeps re-running it for as long as the project stays open.

No prompt

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands Cybersecurity researchers have called attention to a new modular malware called TELEPUZ that’s been spreading via websites infected

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models

GLM-5.3: Frontier Coding with Emergent Cyber Capabilities

GLM-5.3: Frontier Coding with Emergent Cyber Capabilities Source: Hacker News