this post was submitted on 21 Jul 2026
4 points (100.0% liked)

Security

2136 readers
1 users here now

A community for discussion about cybersecurity, hacking, cybersecurity news, exploits, bounties etc.

Rules :

  1. All instance-wide rules apply.
  2. Keep it totally legal.
  3. Remember the human, be civil.
  4. Be helpful, don't be rude.

Icon base by Delapouite under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS
 

After loading a project, Cursor attempts to find git binaries at various locations including the current workspace. By creating a repository with a planted malicious git.exe in the root, the IDE will execute it with no user interaction and no prompting of the user. This occurs repeatedly on a cadence.

you are viewing a single comment's thread
view the rest of the comments
[–] artwork@lemmy.world 6 points 1 week ago* (last edited 1 week ago)

...Report initially closed as Informative and out of scope...
Report reopened...
...
2026-02-16 - Update requested, no response received
2026-03-03 - Update requested, no response received
...
2023-03-17 - Direct outreach to Cursor CISO requesting update
2026-03-18 - HackerOne indicates Cursor has been contacted
2026-04-01 - Update requested, no response received...

Source

Thankfully, never used, will never use.

Related: https://news.ycombinator.com/item?id=48913340