
Cursor 0-Day Allows Arbitrary Code Execution by Simply Opening a Repository
A newly disclosed Cursor IDE vulnerability demonstrates how opening an untrusted repository on Windows could lead to arbitrary code execution without prompt injection, AI-agent interaction, or any additional user approval. While the original issue centered on malicious git.exe binaries, subsequent research found the attack surface extended to other executables, including hatch.exe, under specific project conditions. […]
The post Cursor 0-Day Allows Arbitrary Code Execution by Simply Opening a Repository appeared first on Cyber Security News.