After loading a project, Cursor attempts to find git binaries at various locations including the current workspace. By creating a repository with a planted malicious git.exe in the root, the IDE will execute it with no user interaction and no prompting of the user. This occurs repeatedly on a cadence.
Cursor 0day: When Full Disclosure Becomes the Only Protection Left - Mindgard
https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left
1 Comments
artwork@lemmy.world · 7 pts · 37d
Thankfully, never used, will never use.
Related: https://news.ycombinator.com/item?id=48913340