A proof-of-concept (PoC) demonstrated a vulnerability in Cursor version 3.2.16 on Windows, where opening a malicious repository could cause the application to execute a disguised git.exe file located in the repository's root. Researchers disguised the Windows Calculator as git.exe to show that Cursor would launch it without user confirmation. While Cursor's developers consider this a user responsibility issue related to workspace trust, security experts recommend opening unknown repositories in isolated environments like Windows Sandbox and implementing path-based execution restrictions. AI
IMPACT This vulnerability highlights the need for enhanced security practices when using AI-powered development tools with external code repositories.
RANK_REASON The cluster details a specific vulnerability in a software tool (Cursor IDE) and discusses mitigation strategies, fitting the 'tool' category.
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →