Unpatched Cursor Vulnerability Exposes Users to Code Execution

Cursor Vulnerability Exposes Users to Code Execution, Leaving Millions Unpatched

A critical vulnerability in Cursor, a popular AI-assisted development environment used by over 7 million active users, has been left unpatched for seven months. The flaw allows attackers to execute malicious code when a developer opens a project containing a specially crafted git.exe binary in the repository root.

The security issue arises from Cursor’s path resolution logic, which automatically executes any executable found in the workspace without warning or approval. This means that if an attacker plants a malicious git.exe file at the repository root, Cursor will execute it without notifying the user. The vulnerability is not complex and can be exploited simply by opening a project containing a malicious binary.

The issue was reported to Cursor on December 15, 2025, but despite repeated attempts to bring attention to the problem, including submitting the vulnerability to its bug bounty program, no patch has been released. Mindgard, the security research firm that discovered the flaw, has chosen to disclose it publicly in an effort to raise awareness and encourage users to take action.

The unpatched Cursor vulnerability is a concerning development, particularly given the widespread use of the tool among developers. The fact that Cursor’s CISO invited Mindgard to participate in its bug bounty program on HackerOne without providing any indication of a fix being worked on or communicated to affected organizations raises questions about the company’s commitment to user security.

The cursor vulnerability is not an isolated incident, but rather part of a larger trend of unpatched vulnerabilities leaving users exposed. It highlights the need for companies like Cursor to prioritize user security and take responsibility for addressing critical flaws in their products.

As developers, it is essential to be aware of this vulnerability and take steps to protect themselves and their teams. This can include checking for updates and patches regularly, verifying the authenticity of files before opening them, and using reputable tools and services. By staying informed and taking proactive measures, users can reduce their exposure to such threats.

In light of this development, it is crucial that Cursor takes immediate action to address the vulnerability and notify its affected users. The company must prioritize user security and take concrete steps to prevent similar incidents in the future. As a community, we must also remain vigilant and continue to advocate for better cybersecurity practices across the industry.


Source: SecurityWeek — 2026-07-15