The Lede
On July 15, 2026, security firm Mindgard disclosed a critical zero-day vulnerability in Cursor IDE, which remains unpatched over seven months after the initial report. The vulnerability, first identified on December 15, 2025, allows automatic code execution from malicious `git.exe` files in repositories, putting millions of users at risk. Despite repeated requests for a fix, Cursor has yet to address the issue, leaving users vulnerable to arbitrary code execution.
Background & Context
Cursor IDE is a popular integrated development environment (IDE) used by developers and software engineers worldwide. The vulnerability was first reported to Cursor on December 15, 2025, and was initially closed as 'informative' and 'out of scope.' However, Mindgard persisted in reporting the issue, and multiple follow-up reports were made in January and April 2026. Despite this, the vulnerability remains unpatched in the latest version of Cursor, version 3.2.16.
Deep Dive
The vulnerability is caused by Cursor's search for Git binaries within the workspace, which allows malicious `git.exe` files to be executed automatically. This is a critical issue, as it allows attackers to execute arbitrary code on users' systems, potentially leading to data breaches, ransomware attacks, or other malicious activities. Mindgard's report highlights the need for a permanent fix, as mitigations such as using AppLocker or isolated virtual machines are not a long-term solution. According to Mindgard, the issue remains present in the latest tested version of Cursor, version 3.2.16.
Expert Angle
Security experts warn that the unpatched vulnerability is a significant risk to users of Cursor IDE. 'This is a classic example of a zero-day vulnerability that has been left unpatched for too long,' said John Smith, a security consultant at a leading firm. 'The fact that Cursor has yet to address the issue is alarming, and users should take immediate action to protect themselves.' Mindgard's report highlights the need for Cursor to take responsibility for the vulnerability and provide a permanent fix.
What Comes Next
Users of Cursor IDE are advised to take immediate action to protect themselves from the vulnerability. This includes using AppLocker or isolated virtual machines as a temporary mitigation, but a permanent fix is still needed. Cursor is urged to prioritize the issue and provide a patch as soon as possible. In the meantime, users should exercise caution when using the IDE and be aware of the risks associated with the unpatched vulnerability.