Cursor IDE Binary Planting Code Execution

Affected Vendor(s)

Affected Product(s)

Summary

After loading a project, Cursor attempts to find git binaries at various locations including the current workspace. By creating a repository with a planted malicious git.exe in the root, the IDE will execute it with no user interaction and no prompting of the user. This occurs repeatedly on a cadence.

Timeline

Discovered on
December 15, 2025
Disclosed to Vendor on
December 15, 2025
Published on
July 14, 2026

Credit

Blog Post

References