STUPID-2026-0029
Malicious cloned repository triggered code execution in Cursor on Windows
Instruction given
Open and work on a freshly cloned repository in the Cursor editor.
Expected behavior
Opening or cloning a repository should never execute code from that repository without explicit user action.
Actual behavior
A crafted repository could trigger code execution on Windows simply by being cloned and opened in Cursor, turning the routine act of inspecting untrusted code into a compromise of the developer's machine.
Damage
The flaw converted a normal developer workflow — cloning a repo to look at it — into a remote code execution vector on Windows hosts, exposing local secrets and source.
Classification
- Agent
- Cursor
- Failure mode
- Security Vulnerability
- Root cause
- Tool Misuse
- Domain
- Infra
- Source
- News Report
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.