Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay
Article excerpt
Highlighted: the sentence this signal was extracted from
Opening a Git repository in a vulnerable version of Cursor could be enough to give attackers code execution on a developer's Windows machine. Security researchers at Mindgard discovered that Cursor would execute a malicious git.exe file planted in the root of a cloned repository, allowing attacker-controlled code to run with the logged-in user's privileges. The company quietly patched the flaw roughly seven months after receiving a private disclosure, shortly before researchers made the vulnerability public. Seven months after the vulnerability was initially disclosed, Cursor has silently patched it, just before Mindgard's public disclosure of the issue. Because AI coding assistants sit at the center of development workflows, weaknesses in how they launch trusted tools can expose developers during routine tasks such as cloning repositories. As these tools become more embedded in everyday developer workflows, longstanding security weaknesses such as untrusted search paths can have far greater consequences because the editor itself becomes part of the execution chain. Mindgard, a cybersecurity firm, said it discovered the vulnerability last year and privately disclosed it to Cursor on Dec. 14. The vulnerability stems from how Cursor handles Git files during project initialization. According to a Proof of Concept demonstration from Mindgard, as cited by Latest Hacking News...
Keep reading with a free account
The rest of this article, and every signal for Cursor, is in your free account.
