Mark RadarMARK RADAR
EN

Unpatched Cursor Flaw Lets Malicious Repositories Run Code

1 reports · First detected 2026-07-20 · Last active 2026-07-20

Cursor, a widely used AI coding assistant, integrates closely with local development environments to help programmers navigate and generate code. Cybersecurity firm Mindgard said that integration creates a potential attack path when the tool handles Git executables inside an untrusted project. The finding highlights a broader software-supply-chain risk as AI development tools gain access to source code, command-line utilities and other resources on developers’ machines.

Mindgard disclosed an unpatched Cursor vulnerability that allows an attacker to place a malicious git.exe file in a project’s root directory. Opening the booby-trapped repository could then trigger arbitrary code execution without an additional deliberate launch by the developer. No patched release was available as of the report’s publication. Security specialists advised restricting executable searches to approved working directories and opening unfamiliar repositories inside a virtual machine, container or other isolated environment.

All Coverage

1 original reports

The Backstory

The history behind this event
Cursor Security Flaws Allow Sandbox Bypass and Arbitrary Code Execution2026-07-02 · 1 reports · similarity 0.88

Cursor is a widely used AI coding tool that can read project content and invoke system functions, making its sandbox an important defense for isolating untrusted instructions. Cato Networks said prompt injection that crosses this boundary could place malicious code directly inside development environments, putting source code, credentials and companies’ internal systems at risk.

Cato Networks security researchers recently disclosed two critical vulnerabilities collectively dubbed “DuneSlide.” Attackers could launch a prompt-injection attack when a victim processes malicious content, bypassing Cursor’s sandbox and executing arbitrary system commands. Cursor patched the flaws in version 3.0. As of the disclosure, the company had not reported the number of affected users or the value of any actual losses. Users should upgrade as soon as possible.

CursorJacking Design Flaw in AI Code Editor Could Expose Developers’ API Keys2026-04-30 · 1 reports · similarity 0.84

Cursor, an AI code editor developed by Anysphere, uses models and extensions to assist with software development and debugging. Cybersecurity research firm LayerX said Cursor stores API keys and connection tokens in a local SQLite database, potentially putting developers’ cloud services, source code and enterprise systems at risk if access controls are inadequate.

LayerX recently disclosed a design flaw dubbed “CursorJacking” that allows malicious third-party extensions to read Cursor’s local database and steal API keys and connection tokens. As of July 20, 2026, Anysphere had not announced a patch, a remediation date or the amount of any losses. Users should avoid installing extensions from unknown sources for now.

Mark Radar|MARK RADAR