Cursor IDE 0day: opening a malicious repo auto-executes code, unfixed for 6 months
Cursor IDE 0day 漏洞:打开恶意仓库即可自动执行任意代码
Mindgard found a Cursor vulnerability: on Windows, opening a repo that contains a malicious git.exe in its root causes Cursor to execute it automatically—no prompt, no click, no warning. No model manipulation or privilege escalation needed; just trick a dev into opening a project. First reported Dec 15, 2025. Over 6 months and 197+ releases later, it remains unpatched. Cursor's security automation failed initially; later HackerOne closed the report as Informative/out of scope, then reopened after challenge. No official fix timeline is given. Workarounds: enterprise admins can use AppLocker path-based deny rules for git.exe in workspace dirs; consumers should open untrusted repos only in a VM or Windows Sandbox.
Why it matters: Zero-click RCE affecting Cursor on Windows with trivially low attack bar. Full disclosure after 6 months of no fix, with clear mechanism and timeline. Docked slightly because it's security research not a product update, and Windows-only, but dev audience resonance is extremely...