Mark RadarMARK RADAR
About
EN
Sign in

Unpatched Cursor Flaw Lets Malicious Repositories Run Code

1 reports · First detected 2026-07-20 · Last active 2026-07-20

Cursor, a widely used AI coding assistant, integrates closely with local development environments to help programmers navigate and generate code. Cybersecurity firm Mindgard said that integration creates a potential attack path when the tool handles Git executables inside an untrusted project. The finding highlights a broader software-supply-chain risk as AI development tools gain access to source code, command-line utilities and other resources on developers’ machines.

Mindgard disclosed an unpatched Cursor vulnerability that allows an attacker to place a malicious git.exe file in a project’s root directory. Opening the booby-trapped repository could then trigger arbitrary code execution without an additional deliberate launch by the developer. No patched release was available as of the report’s publication. Security specialists advised restricting executable searches to approved working directories and opening unfamiliar repositories inside a virtual machine, container or other isolated environment.

All Coverage

1 original reports

The Backstory

The history behind this event
Sandbox Flaws Let Cursor, Codex and Gemini Agents Reach Host Systems2026-07-21 · 1 reports · similarity 0.81

AI coding agents can edit files and run shell commands, making sandboxing a critical barrier against mistakes, prompt injection and malicious repositories. Pillar Security said Cursor, OpenAI’s Codex CLI, Google’s Gemini CLI and Antigravity exposed indirect paths around that boundary. Rather than breaking isolation directly, an agent could alter workspace settings, Git configuration or Python virtual-environment files that trusted tools later execute outside the sandbox; in some setups, Docker could also provide access to the host.

The findings were reported on July 21, 2026. Cursor’s Python virtual-environment flaw affected releases before 3.1.2 and was fixed in 3.1.2, while CVE-2026-48124 affected Cursor Desktop 2.4.37 and was patched in 3.0.0. OpenAI corrected Codex CLI’s incomplete validation of supposedly safe Git commands in version 0.95.0. Pillar also described a macOS scenario involving Docker Desktop, Dev Containers CLI and network-enabled Auto-Run Sandbox mode that could let an agent access a user’s home directory and run host commands without another approval prompt.

Cursor Security Flaws Allow Sandbox Bypass and Arbitrary Code Execution2026-07-02 · 1 reports · similarity 0.88

Cursor is a widely used AI coding tool that can read project content and invoke system functions, making its sandbox an important defense for isolating untrusted instructions. Cato Networks said prompt injection that crosses this boundary could place malicious code directly inside development environments, putting source code, credentials and companies’ internal systems at risk.

Cato Networks security researchers recently disclosed two critical vulnerabilities collectively dubbed “DuneSlide.” Attackers could launch a prompt-injection attack when a victim processes malicious content, bypassing Cursor’s sandbox and executing arbitrary system commands. Cursor patched the flaws in version 3.0. As of the disclosure, the company had not reported the number of affected users or the value of any actual losses. Users should upgrade as soon as possible.

CursorJacking Design Flaw in AI Code Editor Could Expose Developers’ API Keys2026-04-30 · 1 reports · similarity 0.84

Cursor, an AI code editor developed by Anysphere, uses models and extensions to assist with software development and debugging. Cybersecurity research firm LayerX said Cursor stores API keys and connection tokens in a local SQLite database, potentially putting developers’ cloud services, source code and enterprise systems at risk if access controls are inadequate.

LayerX recently disclosed a design flaw dubbed “CursorJacking” that allows malicious third-party extensions to read Cursor’s local database and steal API keys and connection tokens. As of July 20, 2026, Anysphere had not announced a patch, a remediation date or the amount of any losses. Users should avoid installing extensions from unknown sources for now.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)