Security firm Mindgard publicly discloses unpatched Cursor code-execution flaw after seven-month stall
Mindgard published full details of an unpatched Cursor IDE flaw that runs a malicious 'git.exe' automatically, seven months after first reporting it to the vendor.
Security firm Mindgard published full technical details on July 14 of an unpatched code-execution flaw in the Cursor AI coding editor, seven months after first reporting it to the vendor.
Opening a cloned repository in Cursor on Windows that contains a malicious file named “git.exe” at its root causes the editor to run that binary automatically, with no prompt or warning, handing an attacker arbitrary code execution as the logged-in user, Mindgard said. Cursor has more than 7 million active users across over 50,000 companies, according to the firm, making a silent code-execution path a wide exposure.
Mindgard first reported the issue on December 15, 2025. It says Cursor’s HackerOne program initially closed the report as “informative and out of scope” before reopening it, and that Cursor’s chief information security officer acknowledged in January that an internal process had failed to invite the firm to the private program. Mindgard says it sent multiple unanswered status requests between February and June before going public.
No patch or public advisory existed as of the July 14 disclosure, Mindgard said, after it reviewed all 33 of Cursor’s published advisories. The account is the researcher’s own timeline of the disclosure; the underlying flaw is a documented behavior of how the editor handles binaries in a cloned repo.
A Cursor spokesperson later said the issue was addressed on July 13 and that the company would contact Mindgard. Mindgard says it found similar unpatched or downgraded behavior in GitHub Copilot CLI, Google’s Gemini CLI and OpenAI’s Codex, suggesting the risk is not unique to one AI coding tool.
More news

AWS releases six open-source Hugging Face deployment skills for SageMaker

Google Research releases MilleMiglia logistics benchmark generator

AWS launches AgentCore Runtime V2 with elastic memory and snapshot starts
