Cursor Security Bug Allowed Repositories to Execute Commands Before Trust Verification
AI summary · glm-5.3
Cursor fixed a pre-trust bug letting untrusted repositories execute commands, then closed the report as informative.
A security flaw in the Cursor editor allowed repositories to execute commands before the user completed workspace trust verification. Cursor fixed the pre-trust code execution path within three days of receiving the report. The vendor then closed the report as informative, disputing the severity of the behavior.
- Repositories could execute commands before workspace trust was granted
- Fix shipped three days after the report
- Cursor closed the report as informative, disputing severity
Full article
Cursor fixed a pre-trust code execution path in three days then closed the report as informative
This source does not provide full text. Read it at infosecurity-magazine.com.