THREAT OPS › Threat News › Bug in Cursor Allows Simple RCE
Bug in Cursor Allows Simple RCE
<p class="wp-block-paragraph">There is a critical zero-day vulnerability in Cursor, a widely adopted AI-assisted integrated development environment that has been present for at least eight months and has gone unresolved, despite efforts from security researchers who reported the bug to Cursor in December. The flaw allows for arbitrary code execution on Windows systems simply by opening a repositor
MITRE ATT&CK techniques
Indicators of compromise
- https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-lefturl
Original source: https://decipher.sc/2026/07/15/bug-in-cursor-allows-simple-rce/