← All stories
● Covered by 3 sources · 3 reportsMedium impact

Critical Vulnerability in Cursor IDE Allows Arbitrary Code Execution on Windows

🔄 Updated 78d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Vulnerability allows arbitrary code execution via malicious git binaries.
  • Cursor IDE affects over 7 million users, remains unpatched.
  • Discovered by Mindgard, reported December 2025.
  • Cursor executes 'git.exe' from project roots without warnings.
  • No patch or advisory has been released by Cursor.

Overview of the Vulnerability

A critical vulnerability in Cursor IDE allows arbitrary code execution by executing malicious git binaries found in project roots on Windows. This issue risks exposing user credentials and compromising system security without any prior interaction from the user.

Affected Users and Systems

Cursor, a widely-used AI-assisted development environment, has over 7 million active users. This unpatched vulnerability exposes a significant number of developers to potential security threats, as the IDE executes 'git.exe' files without user prompts or warnings.

Discovery and Response

Mindgard, an AI security firm, identified and reported the vulnerability to Cursor on December 15, 2025. Despite multiple disclosures, Cursor has not released a patch or provided an advisory, leaving users vulnerable to potential exploitation.

Technical Details

The flaw involves Cursor looking for Git binaries in multiple locations, including the workspace, when a project is loaded. If a malicious 'git.exe' file is placed in the root of a repository, it will be executed automatically, leading to arbitrary code execution.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

An unpatched vulnerability in Cursor on Windows permits code execution by executing a malicious git.exe when a developer opens a repository. This security flaw affects over 7 million users and remains unaddressed by the Cursor team after multiple disclosures.

A vulnerability in Cursor allows arbitrary code execution simply by opening a repository containing a 'git.exe' file, risking user credentials and system security. Despite being reported in December 2025, Cursor has not released a patch or advisory, leaving users exposed.

A critical vulnerability in Cursor IDE enables arbitrary code execution by executing malicious git binaries found in project roots, posing significant security risks. Despite being reported over six months ago by Mindgard, the issue remains unpatched, potentially affecting over 7 million users.