Cursor AI Code Editor RCE Flaw Allows Automatic Malware Execution

Post Reply
Shane1145
Posts: 1689
Joined: Wed Sep 25, 2024 2:31 pm

Cursor AI Code Editor RCE Flaw Allows Automatic Malware Execution

Post by Shane1145 »

A critical remote code execution (RCE) vulnerability has been identified in the Cursor AI Code Editor that allows an attacker to execute arbitrary commands on a developer’s machine the moment a project folder is opened.

Discovered by the research team at Oasis Security, the flaw exploits a default configuration in Cursor that mirrors Visual Studio Code’s “Workspace Trust” feature but leaves it disabled by default, bypassing any user consent prompts.

https://cyberpress.org/cursor-ai-code-editor-rce-flaw/
Post Reply