top of page

Unpatched security vulnerability in Cursor AI application threatens developer security

Cursor is currently one of the most highly anticipated AI-integrated development environments (IDEs), boasting a large user community of over 7 million active members. However, a recent report from cybersecurity organization Mindgard has highlighted a dangerous vulnerability in the Windows version of this application, allowing malicious actors to execute code directly on developers' machines.

A surprisingly simple attack vector

According to Mindgard's analysis, this security flaw is remarkably easy to exploit. When a developer opens a project repository using the Cursor application, the software automatically triggers a malicious executable file named git.exe located right in the project's root directory. This process occurs completely automatically, without displaying any warnings or requiring user confirmation.

Cursor security vulnerability is surprisingly easy to exploit
Cursor security vulnerability is surprisingly easy to exploit

Notably, this attack vector does not require sophisticated or complex techniques. Mindgard emphasized that the vulnerability does not rely on deep exploit chains, AI model manipulation (such as prompt injection or jailbreaking), buffer overflows, or other high-tech tricks typically associated with hackers. The risk simply stems from the user action of opening a project folder that contains a malicious git.exe file.

Root cause of the security vulnerability

This issue stems from the system's operational mechanism. Specifically, during the loading and setup of a new project, Cursor scans and searches for Git command files across various directories to facilitate its work. Unfortunately, this search path includes the active workspace itself.

Due to this internal path resolution mechanism, if an attacker secretly places a spoofed git.exe file in the project's root directory, Cursor will identify and automatically execute it. Users are left with no indicators or tools to realize that malicious software is about to be launched on their devices.

A silent response from Cursor

Mindgard stated that they proactively submitted a detailed report of this vulnerability to the Cursor development team on December 15, 2025. However, during the subsequent seven months, they received no response regarding a potential fix.

In the following January, Cursor's Chief Information Security Officer (CISO) invited Mindgard to resubmit the bug report through their bug bounty program on the HackerOne platform. Although the vulnerability was subsequently confirmed as successfully reproducible, Cursor continued to maintain its silence and has yet to issue a definitive fix.

A representative from Mindgard shared that coordinated vulnerability disclosure only truly makes sense when there is cooperation from both sides. After waiting for over half a year without any sign of user protection or alerts sent to affected organizations, Mindgard decided to make this information public. They believe that continuing to keep the vulnerability secret no longer benefits the community but only covers up the vendor's delay.

Currently, technology news outlet SecurityWeek has contacted Cursor via email for clarification but has yet to receive an official response from the company.

The automatic code execution vulnerability in Cursor demonstrates that even advanced AI-powered tools can harbor basic oversights in how they handle system data. With no official patch released by the developer yet, Cursor users on Windows must be exceptionally cautious when opening project repositories from unknown or untrusted sources.

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page