>_ Posts
Blog
Thoughts on development, engineering, and product.
1 post
- 01|
Opening a folder in Cursor can run malicious code by itself — and Cursor has known for seven months
An unpatched zero-day in Cursor for Windows lets any repository with a forged git.exe in its root execute code automatically, with no click, no warning, no confirmation. Mindgard reported it in December 2025; it went fully public in July 2026, after seven months of silence.