Unpatched Cursor for Windows flaw can run malicious code when a developer opens a repository

A newly disclosed Cursor vulnerability on Windows can let a malicious project run code on a developer’s computer as soon as the repository is opened. Mindgard says Cursor's path-resolution logic will automatically execute a git.exe file placed in the repository root, without warning or approval. No CVE is cited in the article, and the issue remained unpatched after a reported seven-month disclosure period.
Why it matters: This affects developers and organizations using Cursor on Windows, especially those opening third-party or recruiter-sent code projects. Treat untrusted repositories as dangerous and avoid opening them in Cursor on Windows until Cursor ships a fix or mitigation.

Sources

Unpatched Cursor Vulnerability Exposes Users to Code Execution
Ionut Arghire 2026.07.15 100% relevant
This article appears to be the first cited report here establishing a distinct Cursor-on-Windows code-execution flaw caused by automatic execution of a repository-root git.exe, and it does not match the previously tracked Cursor DuneSlide prompt-based sandbox escape story.
← Back to all stories