Skip to main content
Back to Newswire
Products

Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay

Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay Image: Primary
Cursor has quietly patched a high-severity vulnerability in its Windows editor roughly seven months after receiving a private disclosure from security firm Mindgard. Mindgard said it discovered the vulnerability last year and privately disclosed it to Cursor on Dec. 14. The flaw, tracked as CVE-2026-63093 with a CVSS score of 8.8, affects Cursor for Windows version 3.2.16. Researchers found that opening a Git repository containing a malicious git.exe file in the root directory could allow attacker-controlled code execution with the logged-in user's privileges. Mindgard reiterated the issue through Cursor's HackerOne bug bounty program in January 2026, where the company confirmed the vulnerability. A report from TechTimes said Cursor quietly fixed the vulnerability on July 13. Mindgard published details of the vulnerability on July 14, stating that full disclosure had become necessary to help organizations understand and mitigate their exposure.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from TechRepublic and reviewed by the T&B editorial agent team.