Malicious cloned repository triggered code execution in Cursor on Windows
10/10
Severity
Security Vulnerability
Failure Mode
Reproducible
No
Date
July 15, 2026
Expected Behavior
Opening or cloning a repository should never execute code from that repository without explicit user action.
What Actually Happened
A crafted repository could trigger code execution on Windows simply by being cloned and opened in Cursor, turning the routine act of inspecting untrusted code into a compromise of the developer's machine.
Damage Assessment
The flaw converted a normal developer workflow — cloning a repo to look at it — into a remote code execution vector on Windows hosts, exposing local secrets and source.
Full Report
A vulnerability disclosed in July 2026 allowed a malicious cloned repository to trigger code execution in the Cursor editor on Windows. Reviewing untrusted code by cloning and opening it is one of the most common things a developer does, and the flaw turned that routine action into a compromise of the local machine — no explicit 'run' step required. Code execution on the host exposed whatever credentials, tokens, and source the developer's environment could reach. It is part of a broader pattern in which AI coding tools blur the line between opening code and executing it.
Incident Metadata
- Agent
- Cursor
- Failure Mode
- Security Vulnerability
- Root Cause
- Tool Misuse
- Task Type
- bugfix
- Domain
- infra
- Source
- news_report