Cursor Patched a Silent Repo-Poisoning Zero-Day With No Advisory and No CVE cursor.com Clone a stranger's repository and open it in Cursor on Windows. That is the entire exploit. If the repository contains a file named`git.exe` at its root, the AI IDE runs it immediately — no click, no approval di...
Cursor Patched a Silent Repo-Poisoning Zero-Day With No Advisory and No CVE
cursor.com
Clone a stranger's repository and open it in Cursor on Windows. That is the entire exploit. If the repository contains a file namedgit.exe at its root, the AI IDE runs it immediately — no click, no approval dialog, no warning — with the full privileges of the logged-in developer. The attacker's code executes, and it keeps executing, repeatedly, for as long as the project stays open.
Cursor quietly fixed this on July 13, 2026, one day before AI security firm Mindgard published its full technical writeup after a seven-month disclosure process that produced silence, a broken bug bounty automation, an initial rejection, and no status updates. As of July 17, the company has issued no public security advisory, assigned no CVE, and told no one which version number contains the fix, according to reporting by Dark Reading and The Hacker News.
Cursor serves more than 7 million active users, more than 1 million daily active users, and more than 1 million paying subscribers across more than 50,000 companies. Developers who have not updated to the patched build are unaware they were ever at risk.
Update Cursor immediately. The company told Dark Reading it addressed the issue on July 13, but has not publicly identified the patched version number. Updating to the most recent available build is the only confirmed mitigation.
For managed Windows environments where an immediate update is not possible: administrators can deploy AppLo
Cursor Patched a Silent Repo Poisoning Zero Day With No Advisory and No CVE cursor.com Clone a stranger's repository and open it in Cursor on Windows.
If the repository contains a file named git.exe at its root, the AI IDE runs it immediately — no click, no approval dialog, no warning — with the full privileges of the logged in developer.
The attacker's code executes, and it keeps executing, repeatedly, for as long as the project stays open.
Continue reading