Skip to main content
Products

Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay

Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay Image: Primary
Cursor has quietly patched a high-severity vulnerability in its Windows editor roughly seven months after receiving a private disclosure from security firm Mindgard. Mindgard said it discovered the vulnerability last year and privately disclosed it to Cursor on Dec. 14. The flaw, tracked as CVE-2026-63093 with a CVSS score of 8.8, affects Cursor for Windows version 3.2.16. Researchers found that opening a Git repository containing a malicious git.exe file in the root directory could allow attacker-controlled code execution with the logged-in user's privileges. Mindgard reiterated the issue through Cursor's HackerOne bug bounty program in January 2026, where the company confirmed the vulnerability. A report from TechTimes said Cursor quietly fixed the vulnerability on July 13. Mindgard published details of the vulnerability on July 14, stating that full disclosure had become necessary to help organizations understand and mitigate their exposure.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from TechRepublic and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Products
AI Products

OpenAI pauses $200 ChatGPT Pro sign-ups, citing Astra demand

OpenAI has stopped selling the $200 tier of ChatGPT Pro, saying demand for its Astra model is straining its systems, according to TechCrunch reporting cited by The Next Web. Existing subscribers keep their plans, and the $100 Pro...

AI Products
AI Products

SemiAnalysis acquires Citrini Research; founder plans new fund

Citrini Research founder James van Geelen has sold the independent investment-research firm to SemiAnalysis, a semiconductor and AI research shop, for an undisclosed sum, according to Bloomberg. Sources told the outlet that van G...