ZeroHour
Infosecurity Magazinepublished ()ingested

Cursor Security Bug Allowed Repositories to Execute Commands Before Trust Verification

mediumVulnerabilityimportance 50
AI summary · glm-5.3

Cursor fixed a pre-trust bug letting untrusted repositories execute commands, then closed the report as informative.

A security flaw in the Cursor editor allowed repositories to execute commands before the user completed workspace trust verification. Cursor fixed the pre-trust code execution path within three days of receiving the report. The vendor then closed the report as informative, disputing the severity of the behavior.

  • Repositories could execute commands before workspace trust was granted
  • Fix shipped three days after the report
  • Cursor closed the report as informative, disputing severity
Full article

Cursor fixed a pre-trust code execution path in three days then closed the report as informative

This source does not provide full text. Read it at infosecurity-magazine.com.