STUPID-2026-0029

Malicious cloned repository triggered code execution in Cursor on Windows

10.0critical
July 15, 2026Verified
  1. Instruction given

    Open and work on a freshly cloned repository in the Cursor editor.

  2. Expected behavior

    Opening or cloning a repository should never execute code from that repository without explicit user action.

  3. Actual behavior

    A crafted repository could trigger code execution on Windows simply by being cloned and opened in Cursor, turning the routine act of inspecting untrusted code into a compromise of the developer's machine.

  4. Damage

    The flaw converted a normal developer workflow — cloning a repo to look at it — into a remote code execution vector on Windows hosts, exposing local secrets and source.

A vulnerability disclosed in July 2026 allowed a malicious cloned repository to trigger code execution in the Cursor editor on Windows. Reviewing untrusted code by cloning and opening it is one of the most common things a developer does, and the flaw turned that routine action into a compromise of the local machine — no explicit 'run' step required. Code execution on the host exposed whatever credentials, tokens, and source the developer's environment could reach. It is part of a broader pattern in which AI coding tools blur the line between opening code and executing it.

Classification

Agent
Cursor
Root cause
Tool Misuse
Domain
Infra

Related incidents

Get told when an agent breaks something

We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.

This database is callable over MCP — query it from inside your agent.