Cursor can execute a malicious file from a repository

Cursor is an AI-powered code editor used to generate, review and modify code. Mindgard has disclosed a Windows vulnerability in which opening a repository containing a malicious git.exe file in its root could cause Cursor to execute it without prompting. Cursor states the issue is limited to Windows and requires the user to open an untrusted repository containing the executable. The vendor recommends enforcing Workspace Trust so unknown folders open in restricted mode. Organisations should also consider application controls and disposable environments when reviewing external code.

What this means for your organisation

Developer machines are among the most valuable endpoints an organisation has. They hold source code, access keys, production credentials and often far looser restrictions than other clients. At the same time, pulling down an unfamiliar repository to look at it is entirely routine work. When the tool executes something from that repository without asking, the distance from curiosity to compromise is short.

Berigo recommends

  • Enforce Workspace Trust centrally in Cursor so unknown folders always open in restricted mode.
  • Establish a rule that external code is reviewed in disposable environments or containers, not on the developer's own machine.
  • Bring AI coding tools into the approved software portfolio with a named owner, version control and update responsibility.
  • Keep developer credentials short-lived so a compromised development environment does not yield lasting production access.

Source

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch