Observed Signal · Jul 15, 2026 · Vulnerability Disclosure · Source: DEV Community · Impact: 3/5 · Sentiment: Negative

Cursor has unpatched Windows 0-day for seven months

Executive Signal Summary

A security researcher from Mindgard discovered a trivial but high-impact vulnerability in Cursor on December 15, 2025: when opening a repository on Windows, Cursor searches the workspace root for Git binaries and will automatically execute a file named git.exe found there, running code with the user's privileges without prompts. Mindgard reported the issue the same day via Cursor's security contact and through HackerOne, but after process delays and months of follow-ups there was no public fix or status update. After seven months and 197+ Cursor versions, Mindgard published full disclosure on July 15, 2026. The post includes recommended mitigations (AppLocker/App Control rules, using VMs or Sandboxes for untrusted repos) and raises broader trust concerns around AI developer tools that require deep repository access.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

A trivial-to-exploit remote code execution in a widely used developer tool undermines trust in AI dev tooling and exposes many organizations' repos and secrets; it is important operational security news but not industry-shifting like platform-level policy changes.

SIGNAL RADAR

Track Cursor Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • A vulnerability in Cursor causes it to automatically execute a git.exe file placed in a repository root on Windows.
  • Mindgard discovered the issue on 2025-12-15 and reported it the same day.
  • As of 2026-07-15 the issue remained unpatched despite 197+ Cursor versions being released.
  • Mindgard submitted the report through HackerOne; initial handling included automated failures and an initial closure marked 'Informative and out of scope' before reopening.
  • The article states Cursor is used by 7 million developers and 50,000+ companies and that the company raised money at a reported $60B valuation while shipping features during the disclosure window.

Connected Companies & Entities

2 Entities mapped

“Cursor shipped features, raised money at a reported $60B valuation, and announced a SpaceX acquisition....”

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: Jul 15, 2026
Original Coverage Title: “Cursor has an unpatched 0-day. It's been 7 months.”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Security / Developer ToolingAug 5, 2026

One-Click RCE Vulnerability Hits Popular Code Editors

A one-click remote code execution (RCE) vulnerability disclosed on 2026-08-05 affects Cursor, Microsoft Visual Studio Code, and Google Antigravity. The flaw allows attackers to embed malicious commands inside links placed in commit messages; when a developer clicks such a link inside the editor, arbitrary code can run on the developer's machine. The disclosure confirms the attack vector and impact but does not provide affected version numbers, a CVE, or patch details. The article outlines immediate mitigations: audit registered URL schemes, treat commit messages as untrusted, sandbox editors, reduce blast radius for compromised machines, and monitor vendor security advisories for official patches.

Read assessment
Supply Chain AttackJun 8, 2026

Microsoft GitHub Repos Injected with Password-Stealing Malware

Microsoft disabled access to dozens of its open-source GitHub repositories after security researchers flagged malware injected into project code that steals passwords and credentials when developers open the compromised tools in AI coding apps. Affected projects include Azure-related tools and developer integrations for AI coding environments such as Claude Code, Google’s Gemini CLI and VS Code. Security firms Cloudsmith and OpenSourceMalware were among the first to report the incident. At least 70 Microsoft-owned repositories were marked disabled on GitHub. The incident appears related to a recent mid-May compromise of Microsoft’s Durable Task project and has been described by researchers as a potential re-compromise or follow-on breach.

Read assessment
Large Language Models (LLM) & AIJul 21, 2026

AI Agents Can Escape Sandboxes Undetected

Researchers from Pillar Security found that AI agents running in sandboxes can influence files that external tools automatically read, enabling code execution outside the sandbox without the agent breaking any explicit rule. The team reproduced seven findings over several months and published them as the "Week of Sandbox Escapes." Vulnerabilities affected a range of widely used agents and developer tools; affected items included Cursor, OpenAI's Codex, Google's Gemini CLI and Antigravity. Most issues were confirmed and fixed by vendors — for example, Cursor addressed a hook-configuration escape (CVE-2026-48124) in version 3.0.0, and OpenAI patched Codex in version 0.95.0 and paid a high-severity bounty. Pillar Security recommends monitoring when trusted local tools execute files written by agents rather than relying on sandboxes alone.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.