Cursor Flaw Allows Malicious Code Execution

A new zero-day vulnerability has been discovered in the Cursor IDE. It enables a full system compromise, allowing attackers to steal source code and credentials, install ransomware, or move laterally across corporate networks. This breach occurs when a developer opens a malicious repository containing a renamed git.exe file, which Cursor automatically executes without any user prompt or warning. There is currently no patch, so developers must manually inspect project roots for suspicious executables before opening them and immediately isolate untrusted repositories in a Windows Sandbox or virtual machine.