ZeroHour

Search: “Cursor”

70 stories

Cursor Security Bug Allowed Repositories to Execute Commands Before Trust Verification

Cursor fixed a pre-trust bug letting untrusted repositories execute commands, then closed the report as informative.

A security flaw in the Cursor editor allowed repositories to execute commands before the user completed workspace trust verification. Cursor fixed the pre-trust code execution path within three days of receiving the report. The vendor then closed the report as informative, disputing the severity of the behavior.

Infosecurity Magazine · Aug 11, 2026Vulnerability

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

Malicious .git core.fsmonitor configs let attacker code run in AI coding agents like Claude Code and Codex; four of eight flaws remain unpatched.

Manifold Security disclosed eight flaws across seven command-line AI coding agents where a repository's Git core.fsmonitor configuration causes agent-spawned commands to execute attacker code outside the sandbox and without approval prompts. Fixes shipped for goose (CVE-2026-72718, CVSS 4.0 score 7.0), Claude Code on one path, and Cursor, while Hermes Agent, Qwen Code, Grok Build, and a second Claude Code path were still unpatched as of September 1. OpenAI issued three CVEs for the same class in Codex, including CVE-2026-19592, and prior related bugs include CVE-2021-43891 in Visual Studio Code and CVE-2022-24346 in JetBrains IDEs. Exploitation requires the repository to arrive with its .git directory intact, such as via archives, shared drives, or USB sticks rather than an ordinary clone.