Skip to main content
CursorSecurity incident

Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay

What happened

Cursor's AI coding assistant for Windows was found to have a high-severity vulnerability (CVE-2026-63093) that could allow remote code execution if a developer opens a malicious Git repository.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

Opening a Git repository in a vulnerable version of Cursor could be enough to give attackers code execution on a developer's Windows machine. Security researchers at Mindgard discovered that Cursor would execute a malicious git.exe file planted in the root of a cloned repository, allowing attacker-controlled code to run with the logged-in user's privileges. The company quietly patched the flaw roughly seven months after receiving a private disclosure, shortly before researchers made the vulnerability public. Seven months after the vulnerability was initially disclosed, Cursor has silently patched it, just before Mindgard's public disclosure of the issue. Because AI coding assistants sit at the center of development workflows, weaknesses in how they launch trusted tools can expose developers during routine tasks such as cloning repositories. As these tools become more embedded in everyday developer workflows, longstanding security weaknesses such as untrusted search paths can have far greater consequences because the editor itself becomes part of the execution chain. Mindgard, a cybersecurity firm, said it discovered the vulnerability last year and privately disclosed it to Cursor on Dec. 14. The vulnerability stems from how Cursor handles Git files during project initialization. According to a Proof of Concept demonstration from Mindgard, as cited by Latest Hacking News...

Keep reading with a free account

The rest of this article, and every signal for Cursor, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Security incident

What this signalsA breach often leads to new security spend.

Product
Cursor for Windows
Issue
CVE-2026-63093

More security incident signals at other companies

The full record

From the Signal API record

Details

Release type
Version
Issue named
CVE-2026-63093

Topics and mentions

Product tags

  • general technology
  • online technology

Extraction

Confidence
100%
Detected
Jul 28, 2026
signal_type
news
signal_subtype
security_incident

Use this data

Get every security incident signal for Cursor and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Cursor this week?”

  2. Send it to your own tools

    The Signal API returns security incident signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/1ca88306-a1d8-58bf-f941-5ed69573a180 returns this record as JSON. POST /v1/companies/enrich returns every signal for cursor.com.

{
  "signal_id": "1ca88306-a1d8-58bf-f941-5ed69573a180",
  "signal_type": "news",
  "signal_subtype": "security_incident",
  "detected_at": "2026-07-28T17:22:10+00:00",
  "company": {
    "name": "Cursor",
    "domain": "cursor.com"
  },
  "data": {
    "url": "https://www.techrepublic.com/article/news-cursor-git-code-execution-vulnerability-cve-2026-63093/",
    "title": "Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay - TechRepublic",
    "excerpt": "Opening a Git repository in a vulnerable version of Cursor could be enough to give attackers code execution on a developer’s Windows machine. Security researchers at Mindgard discovered that Cursor would execute a malicious git.exe file planted in the root of a cloned repository, allowing attacker-controlled code to run with the logged-in user’s privileges. The company quietly patched the flaw roughly seven months after receiving a private disclosure, shortly before researchers made the vulnerability public. Seven months after the vulnerability was initially disclosed, Cursor has silently patched it, just before Mindgard’s public disclosure of the issue. Because AI coding assistants sit at the center of development workflows, weaknesses in how they launch trusted tools can expose developers during routine tasks such as cloning repositories. As these tools become more embedded in everyday developer workflows, longstanding security weaknesses such as untrusted search paths can have far greater consequences because the editor itself becomes part of the execution chain. Mindgard, a cybersecurity firm, said it discovered the vulnerability last year and privately disclosed it to Cursor on Dec. 14. The vulnerability stems from how Cursor handles Git files during project initialization. According to a Proof of Concept demonstration from Mindgard, as cited by Latest Hacking News , when...",
    "product": "Cursor for Windows",
    "summary": "Cursor's AI coding assistant for Windows was found to have a high-severity vulnerability (CVE-2026-63093) that could allow remote code execution if a developer opens a malicious Git repository.",
    "planning": false,
    "image_url": "https://assets.techrepublic.com/uploads/2026/07/cursor-1.jpg?f=jpeg",
    "confidence": 1,
    "product_data": {
      "name": "Cursor for Windows",
      "full_text": "Cursor for Windows version 3.2.16",
      "fuzzy_match": false,
      "release_type": "version"
    },
    "product_tags": [
      "general_technology",
      "online_technology"
    ],
    "published_at": "2026-07-28T17:22:10Z",
    "vulnerability": "CVE-2026-63093",
    "article_sentence": "Opening a Git repository in a vulnerable version of Cursor could be enough to give attackers code execution on a developer’s Windows machine."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.