BREAKING
Unpatched Cursor Flaw Runs Code on Windows
How the attack fires
1Clone poisoned repo
2git.exe in root
3Cursor runs it
4Re-runs while open
0mo
open unpatched
0+
version releases
0
Cursor v3.2.16
0M
active users
0M
paying users
0
enterprise customers
Risk vs mitigation
The danger
No prompt or approval
Re-runs each open
Windows build affected
Mitigations
AppLocker path rules
Open repos in a VM
Treat repos as untrusted
Sandbox untrusted repos until fixed
AI NEWS BLITZ
Researchers warn an unpatched Cursor flaw can silently run code when you open a repository.