Cursor IDE 0-day vulnerability allows automatic code execution from malicious repositories

iconKuCoinFlash
Share
AI summary iconSummary
On July 15 (UTC+8), security firm Mindgard disclosed a critical zero-day vulnerability in Cursor IDE, affecting CFT compliance and software security. The flaw permits automatic code execution through malicious `git.exe` files in repositories, as Cursor searches for Git binaries within the workspace. Despite being reported over seven months ago, the issue remains unpatched, with over 70 versions released since. Mitigations include using AppLocker or isolated virtual machines. The vulnerability underscores risks under MiCA and increasing regulatory scrutiny.

ME News reports that on July 15 (UTC+8), security firm Mindgard discovered a critical 0day vulnerability in Cursor IDE on December 15, 2025. When a user opens a repository containing a malicious `git.exe` on Windows, Cursor automatically executes the file without any user interaction. The vulnerability arises because Cursor searches for Git binaries in multiple locations, including the workspace, when loading a project. Mindgard reported the issue multiple times over seven months; although Cursor’s CISO acknowledged it, internal automation failures disrupted the remediation process, and over 70 new versions have been released without a fix. Temporary mitigations include using AppLocker to block execution of files with this name from workspace directories, or opening untrusted repositories in an isolated virtual machine. 🔗 Read the original: https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left via AI HOT · https://aihot.virxact.com/items/cmrl6xukw00ogbi7hnn35vq0v (Source: AiHot)

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.