Spyke

Syndicated from the fediverse. Read and engage on the original instance.

View original on programming.dev
security·SecuritybyKissaki

Cursor 0day: When Full Disclosure Becomes the Only Protection Left - Mindgard

After loading a project, Cursor attempts to find git binaries at various locations including the current workspace. By creating a repository with a planted malicious git.exe in the root, the IDE will execute it with no user interaction and no prompting of the user. This occurs repeatedly on a cadence.

Cursor 0day: When Full Disclosure Becomes the Only Protection Left - Mindgardhttps://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-leftOpen linkView original on programming.dev
6

1 reply

...Report initially closed as Informative and out of scope...
Report reopened...
...
2026-02-16 - Update requested, no response received
2026-03-03 - Update requested, no response received
...
2023-03-17 - Direct outreach to Cursor CISO requesting update
2026-03-18 - HackerOne indicates Cursor has been contacted
2026-04-01 - Update requested, no response received...

Source

Thankfully, never used, will never use.

Related: https://news.ycombinator.com/item?id=48913340

7

You reached the end

Cursor 0day: When Full Disclosure Becomes the Only Protection Left - Mindgard | Spyke