Unpatched Cursor Vulnerability Exposes Users to Code Execution
A critical, unpatched vulnerability in Cursor, a popular AI-assisted development environment, allows for code execution simply by opening a project containing a malicious git.exe binary. Despite being reported to Cursor for seven months with no response and a subsequent bug bounty submission, users remain vulnerable, highlighting a significant lack of responsiveness from the vendor.
A critical vulnerability exists within Cursor, a widely used AI-assisted development environment for Windows. According to Mindgard, the issue stems from Cursor’s automatic execution of a git.exe binary when a developer opens a project containing a malicious file in the repository’s root directory. The vulnerability doesn’t require complex exploitation techniques like prompt injection or memory corruption; simply opening a project with a malicious git.exe file triggers the execution. Mindgard reported the vulnerability to Cursor on December 15, 2025, and subsequently submitted it to Cursor’s bug bounty program on HackerOne in January, but the vendor has not yet released a patch. The vulnerability’s ease of exploitation and the prolonged lack of response raise serious concerns about user security and the vendor’s commitment to addressing critical issues. SecurityWeek is awaiting a response from Cursor for further comment.