{"@context":"https://schema.org","@type":"NewsArticle","generatedAt":"2026-07-23T07:21:26.498Z","headline":"Cursor IDE 0day 漏洞：打开恶意仓库即可自动执行任意代码","description":"安全公司 Mindgard 于 2025 年 12 月 15 日发现 Cursor IDE 存在严重 0day 漏洞。当用户在 Windows 上打开包含恶意 `git.exe` 的仓库时，Cursor 会自动执行该文件，无需任何用户交互。漏洞源于 Cursor 在加载项目时会在包括工作区在内的多个位置搜索 Git 二进制文件。Mindgard 在 7 个月内多次报告，Cursor CISO 虽确认但因内部自动化故障导致流程中断，至今已发布 70 多个新版本仍未修复。临时缓解措施包括使用 AppLocker 阻止从工作区目录执行该文件名，或在隔离虚拟机中打开不受信任的仓库。","url":"https://www.aioga.com/news/cmrl6xukw00ogbi7hnn35vq0v/","mainEntityOfPage":"https://www.aioga.com/news/cmrl6xukw00ogbi7hnn35vq0v/","datePublished":"2026-07-14T21:27:11.693Z","dateModified":"2026-07-14T21:27:11.693Z","inLanguage":"zh-CN","publisher":{"@type":"NewsMediaOrganization","name":"Aioga","url":"https://www.aioga.com"},"citation":["https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left","https://aihot.virxact.com/items/cmrl6xukw00ogbi7hnn35vq0v"],"canonicalUrl":"https://www.aioga.com/news/cmrl6xukw00ogbi7hnn35vq0v/","directAnswer":{"@type":"Answer","text":"Mindgard 披露，Windows 用户用 Cursor 打开根目录含恶意 git.exe 的仓库后，IDE 会在无点击、提示或批准的情况下自动执行该文件，形成任意代码执行风险。","url":"https://www.aioga.com/news/cmrl6xukw00ogbi7hnn35vq0v/","dateCreated":"2026-07-14T21:27:11.693Z","author":{"@type":"Organization","@id":"https://www.aioga.com/authors/aioga-editorial/#editorial-team","name":"Aioga Editorial Team","url":"https://www.aioga.com/authors/aioga-editorial/"}},"evidence":[{"@type":"CreativeWork","name":"mindgard.ai source article","url":"https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left","datePublished":"2026-07-14T21:27:11.693Z","provider":{"@type":"Organization","name":"mindgard.ai","url":"https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left"}},{"@type":"CreativeWork","name":"AIHot archive record","url":"https://aihot.virxact.com/items/cmrl6xukw00ogbi7hnn35vq0v","datePublished":"2026-07-14T21:27:11.693Z","provider":{"@type":"Organization","name":"AIHot","url":"https://aihot.virxact.com/items/cmrl6xukw00ogbi7hnn35vq0v"}}],"aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","originalPublisher":{"name":"mindgard.ai","url":"https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left"},"article":{"id":"cmrl6xukw00ogbi7hnn35vq0v","slug":"cmrl6xukw00ogbi7hnn35vq0v","url":"https://www.aioga.com/news/cmrl6xukw00ogbi7hnn35vq0v/","title":"Cursor IDE 0day 漏洞：打开恶意仓库即可自动执行任意代码","title_en":"Cursor 0day：当全面披露成为唯一的防护手段时","summary":"安全公司 Mindgard 于 2025 年 12 月 15 日发现 Cursor IDE 存在严重 0day 漏洞。当用户在 Windows 上打开包含恶意 `git.exe` 的仓库时，Cursor 会自动执行该文件，无需任何用户交互。漏洞源于 Cursor 在加载项目时会在包括工作区在内的多个位置搜索 Git 二进制文件。Mindgard 在 7 个月内多次报告，Cursor CISO 虽确认但因内部自动化故障导致流程中断，至今已发布 70 多个新版本仍未修复。临时缓解措施包括使用 AppLocker 阻止从工作区目录执行该文件名，或在隔离虚拟机中打开不受信任的仓库。","source":"Hacker News 热门（buzzing.cc 中文翻译）","sourceUrl":"https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left","aiHotUrl":"https://aihot.virxact.com/items/cmrl6xukw00ogbi7hnn35vq0v","publishedAt":"2026-07-14T21:27:11.693Z","category":"行业动态","score":83,"selected":true,"articleBody":["Discover shadow AI and agents. Reveal the AI attack surface","Continuously test AI agents & systems against evolving attacks","Find and fix AI security and safety vulnerabilities","Identify and respond to attacks in real time","The vulnerability nobody seems interested in fixing","After loading a project, Cursor attempts to find git binaries at various locations including the current workspace. By creating a repository with a planted malicious git.exe in the root, the IDE will execute it with no user interaction and no prompting of the user. This occurs repeatedly on a cadence.","Sometimes security research uncovers deeply technical vulnerabilities that require pages of explanation. This isn't one of those cases.","This bug is simple. A developer opens a repository in Cursor on Windows, and if that repository contains a malicious git.exe in the project root, Cursor will execute it automatically. There are no clicks, prompts, approval dialogs, or warnings. The result is arbitrary code execution.","Given that Cursor：https://cursor.com/ is one of the most widely adopted AI-assisted development environments (7 million+ active users, 1 million+ daily, 1 million+ paying, used by 50K+ companies), and its reported market price of $60 billion：https://www.forbes.com/sites/richardnieva/2026/06/08/cursor-4-billion-annualized-revenue/, it’s fair to assume that some level of respect for security practices exists, but this issue would indicate otherwise.","The vulnerability was first identified by Mindgard on December 15, 2025. We reported it the same day and multiple times since. More than six months and 197+ new versions later, the issue remains present in the latest tested version of Cursor.","The vulnerability is not theoretical and does not depend on a complex chain of exploitation, prompt injection, model manipulation, jailbreaks, memory corruption, or sophisticated attacker tradecraft. Exploitation simply requires a developer to open a project containing a git.exe binary in the repository at root.","Enterprise/managed windows systems: As a temporary mitigation on managed Windows systems, administrators can use AppLocker or Windows App Control policies to deny execution of the affected executable name from developer workspace directories. Prefer path-based deny rules scoped to repo/workspace roots, such as %USERPROFILE%\\source\\repos\\*\\filename.exe , rather than hash-based rules, because attacker-supplied binaries can vary by hash. Windows does not provide a general built-in rule to block an arbitrary child executable only when launched by a specific parent process, so parent-aware enforcement generally requires EDR or a custom endpoint security product.","Consumer systems: Until the IDE is patched, open untrusted repositories only in an isolated VM, Windows Sandbox, or other disposable environment. Do not rely on file hash blocklists for this issue.","The most confusing part of this disclosure is the absence of a response from Cursor. Over the course of seven months, Mindgard repeatedly attempted to engage through every available channel. Initial disclosure was sent directly to Cursor's security reporting e-mail address, as specified in the company's published security.txt file：https://cursor.com/.well-known/security.txt. Follow-ups were sent when no confirmation was received. Public outreach：https://www.linkedin.com/posts/aaronportnoy_can-anyone-put-me-in-touch-with-a-security-share-7416965166954868736-agkL/ was made in an attempt to identify an appropriate security contact.","Eventually, Cursor's CISO responded and acknowledged that an internal automation failure had prevented the expected HackerOne workflow from taking place. We were invited into the private bug bounty program and resubmitted the report.","The report was initially closed as Informative and out of scope. After we challenged that determination, HackerOne reopened the report, reproduced the issue, and confirmed that the details had been delivered to Cursor. And then everything stopped. Requests for updates went unanswered, additional follow-ups received no response, escalation through HackerOne produced no meaningful engagement, and direct outreach to Cursor leadership yielded the same result: no response.","Month after month has passed without evidence that remediation had begun, that engineering teams were actively investigating the issue, or that affected users would be informed as to the risk. Meanwhile, Cursor continued shipping releases. More than 70 versions came and went as features shipped, announcements continued, and the platform evolved. But the vulnerability remained present and repeated requests for a status update yielded no meaningful response.","At some point the conversation shifts from vulnerability disclosure to a more uncomfortable question: What exactly is the security process for?","The technical issue itself is remarkably straightforward. When loading a project, Cursor attempts to locate Git binaries across multiple locations. One of those locations includes the workspace itself.","If an attacker planted a malicious git.exe in the repository root, Cursor will execute it automatically as part of its path resolution logic without warning, approval, or even an indication that executable content from the repository is about to run.","To demonstrate the issue safely, Mindgard used a harmless proof-of-concept: the Windows Calculator application, renamed to git.exe , placed in the root of the repository. Simply launching Cursor against that repository was enough to execute it.","The screenshot below shows the result. The multiple Calculator windows were not opened manually by the researcher. Cursor continued to re-execute the renamed binary while the project was left open, causing more instances to appear over time. In other words, this was not a one-time launch event or a user-triggered action. Cursor repeatedly invoked executable content from inside the workspace during normal operation.","In a real attack scenario, Calculator would simply be replaced with attacker-controlled code.","The result is arbitrary code execution under the privileges of the current user as demonstrated in the following Sysinternals process monitor logs：https://learn.microsoft.com/en-us/sysinternals/downloads/procmon (last verified on April 30, 2026 against Cursor version 3.2.16 on Windows.)","The vulnerability is almost boring in its simplicity, and that may be the most concerning part. During normal operation, Cursor executes an attacker-controlled binary from a repository with no user interaction required. The fact that such a straightforward issue can persist for months without remediation should concern every individual and organization currently deploying Cursor.","Most coordinated disclosures follow a familiar pattern:","That process works because all parties share a common objective: reducing risk.","Unfortunately, this case never reached the stage of risk reduction. After seven months and no vendor engagement, it’s time to question if remediation for such a simple, high impact vulnerability will ever occur.","Security researchers understand that remediation takes time, particularly inside large and rapidly evolving software platforms. Patience becomes difficult to justify, however, when months pass without communication, updates, or visible progress. Users deserve basic protections against basic threats, and when a vendor stops communicating while continuing to distribute affected software, researchers eventually face an uncomfortable decision:","We believe users deserve the information. Full disclosure is the nuclear option of vulnerability disclosure, reserved for situations where every other path has failed. It exists for a reason: when vendors stop communicating, users should not be left in the dark.","The most obvious question is also the simplest: Why hasn't this been fixed?","The vulnerability is neither subtle nor difficult to reproduce, has a straightforward execution path and critical impact. The lackluster response from Cursor leads to much broader questions:","The security industry has spent years encouraging researchers to use coordinated disclosure channels. Those channels depend on responsive triage processes and vendors having the capacity to evaluate and act on incoming reports. However as AI products proliferate, the volume of security findings is increasing dramatically. Many of those findings are novel and do not fit neatly into traditional vulnerability categories. At the same time, the triage processes we have relied on for nearly two decades are rapidly failing as the core assumptions they are built upon crumble under the emerging world of AI.","If disclosure pipelines are becoming overwhelmed, the industry should say so. Researchers, customers, and users deserve transparency.","Sadly, that may not be the case as uncomfortable questions of priority grow. Like many others, Cursor has been at the center of enormous growth, investment, and industry attention. The company is expanding rapidly, yet from the outside it is difficult to reconcile that growth with the absence of visible progress on a straightforward arbitrary code execution vulnerability.","Rapid growth introduces a responsibility to address security failures while also requiring the treatment of users as valuable customers, not buying experiments. They are trusting production software with access to source code, credentials, proprietary intellectual property, and increasingly, autonomous capabilities.","Trust requires accountability, and accountability requires communication. When users, researchers, and disclosure platforms spend months seeking basic status updates without success, that accountability becomes difficult to see or believe in.","This disclosure goes beyond a single executable named git.exe to the place of trust in software. AI companies routinely ask users to grant unprecedented levels of access to code, repositories, terminals, secrets, and workflows that increasingly blur the line between suggestion and action.","The industry narrative is that these systems deserve trust because they increase productivity, but history has taught us time and again that trust should not be granted because something is useful. It should be earned through behavior. That behavior is reflected in how a company responds to security reports, communicates with affected users, and prioritizes remediation.","When straightforward vulnerabilities remain unresolved for months without meaningful communication, users are forced to reevaluate assumptions about that trust.","Like many security research teams, Mindgard prefers coordinated disclosure. The goal is always security first, publicity second.","But coordinated disclosure only works when there is coordination. Seven months after initial disclosure, we have no indication that users are being protected, that remediation is underway, or that affected organizations have been informed. And at this point, withholding information no longer serves users, it serves silence.","For that reason, Mindgard is releasing full details of this vulnerability. Organizations using Cursor deserve the opportunity to evaluate their exposure, implement compensating controls, and make informed decisions about their security posture.","User safety must come first, even when disclosure becomes uncomfortable.","Especially when disclosure becomes uncomfortable.","See how Mindgard exposes and fixes exploitable AI risk across your AI agents and systems.","Mindgard, the leading provider of AI security solutions, helps enterprises discover, assess, and defend their AI systems. Spun out from over a decade of AI security research at Lancaster University and headquartered in Boston and London, Mindgard combines AI red teaming：https://mindgard.ai/blog/what-is-ai-red-teaming with offensive security expertise and AI research to identify exploitable vulnerabilities in AI models, agents, and applications before attackers do."],"articleImages":[{"sourceUrl":"https://cdn.prod.website-files.com/673f0724df990f6c96bf1867/68dfceeed0e431eab9001c6e_Company%20Name%20%2B%20Shield%20White%20Horizontal%20-%2020241123.png","alt":"","afterParagraph":0,"url":"/media/articles/cmrl6xukw00ogbi7hnn35vq0v/8b593c6eea95194d.png"},{"sourceUrl":"https://cdn.prod.website-files.com/673f0724df990f6c96bf1867/69e68be8a4a5f1bd598dbf70_platform-image.webp","alt":"Screen shot of the Mindgard platform","afterParagraph":0,"url":"/media/articles/cmrl6xukw00ogbi7hnn35vq0v/6f32c678d3c99eb8.webp"},{"sourceUrl":"https://cdn.prod.website-files.com/673f0724df990f6c96bf1867/69ba1bde3ace966f794c7a1f_mega-menu-learn.png","alt":"","afterParagraph":3,"url":"/media/articles/cmrl6xukw00ogbi7hnn35vq0v/8b5b3cb2a195ba03.png"}],"mediaStatus":"ok","articleBodyZh":["发现影子 AI 和代理。揭示 AI 攻击面","持续测试 AI 代理和系统以应对不断演变的攻击","发现并修复 AI 安全和安全漏洞","实时识别并响应攻击","没人似乎有兴趣修复的漏洞","加载项目后，Cursor 会尝试在包括当前工作区在内的多个位置查找 git 二进制文件。通过在根目录创建一个带有恶意 git.exe 的存储库，IDE 将在无需用户交互或提示的情况下执行它。这种情况会反复发生。","有时安全研究会发现需要数页解释的深技术漏洞。但这并不是这种情况。","这个漏洞很简单。在 Windows 上的 Cursor 中打开一个存储库时，如果该存储库在项目根目录中包含一个恶意的 git.exe，Cursor 将自动执行它。没有点击、提示、批准对话框或警告。结果是任意代码执行。","考虑到 Cursor：https://cursor.com/ 是最广泛采用的 AI 辅助开发环境之一（700 万活跃用户，100 万日活，每天 100 万付费用户，被 5 万家公司使用），以及其报告的市场价格 600 亿美元：https://www.forbes.com/sites/richardnieva/2026/06/08/cursor-4-billion-annualized-revenue/，可以合理地认为在某种程度上存在对安全实践的尊重，但此问题表明并非如此。","该漏洞最早由 Mindgard 于 2025 年 12 月 15 日发现。我们当天和之后多次进行了报告。超过六个月和 197 个新版本之后，这个问题在最新测试的 Cursor 版本中仍然存在。","该漏洞不是理论性的，也不依赖复杂的利用链、提示注入、模型操控、越狱、内存损坏或复杂的攻击者技术。利用它只需要开发者打开一个项目，该项目根目录中包含 git.exe 二进制文件即可。","企业/受管理的Windows系统：作为对受管理的Windows系统的临时缓解措施，管理员可以使用AppLocker或Windows应用控制策略来禁止从开发者工作区目录执行受影响的可执行文件。优先使用基于路径的拒绝规则，范围限定在仓库/工作区根目录，例如 %USERPROFILE%\\source\\repos\\*\\filename.exe，而不是基于哈希的规则，因为攻击者提供的二进制文件可能会因哈希不同而变化。Windows没有提供通用内置规则，可以仅在特定父进程启动时阻止任意子可执行文件，因此需要父进程感知的强制执行通常需要EDR或自定义的终端安全产品。","消费者系统：在IDE修补之前，仅在隔离的虚拟机、Windows Sandbox或其他一次性环境中打开不可信的仓库。不要依赖文件哈希阻止列表来解决此问题。","此次披露中最令人困惑的部分是Cursor没有任何回应。在七个月的时间里，Mindgard多次尝试通过各种可用渠道进行沟通。最初的披露是直接发送到Cursor的安全报告电子邮件地址，如公司公开的security.txt文件所示：https://cursor.com/.well-known/security.txt。在没有收到确认的情况下，进行了后续跟进。公开联系：https://www.linkedin.com/posts/aaronportnoy_can-anyone-put-me-in-touch-with-a-security-share-7416965166954868736-agkL/ 是为了尝试找到合适的安全联系人。","最终，Cursor的CISO做出了回应，并承认内部自动化失败导致预期的HackerOne流程未能进行。我们被邀请加入私有漏洞赏金计划，并重新提交了报告。","报告最初被关闭，理由是仅作参考且不在范围内。在我们对这一决定提出质疑后，HackerOne重新打开了报告，复现了问题，并确认细节已传达给Cursor。然后一切停滞。更新请求没有得到回应，额外的跟进也未收到回复，通过HackerOne升级没有产生有效互动，直接联系Cursor的高层也得到了同样的结果：没有回应。","一个又一个月过去了，仍没有任何迹象表明修复工作已经开始，也没有迹象表明工程团队在积极调查该问题，或者受影响的用户会被告知相关风险。与此同时，Cursor 仍在发布新版本。超过 70 个版本陆续推出，在功能发布、公告继续以及平台演进的过程中，该漏洞仍然存在，而针对状态更新的多次请求都没有得到任何有意义的回应。","在某个时刻，谈话从漏洞披露转向了一个更令人不舒服的问题：安全流程究竟是为了什么？","技术问题本身非常简单。当加载一个项目时，Cursor 会尝试在多个位置查找 Git 二进制文件。其中一个位置包括工作区本身。","如果攻击者在仓库根目录中放置了一个恶意的 git.exe，Cursor 将会在其路径解析逻辑中自动执行它，无需警告、批准，甚至不会提示仓库中的可执行内容即将运行。","为了安全地演示该问题，Mindgard 使用了一个无害的概念验证：将 Windows 计算器应用程序重命名为 git.exe，并放置在仓库根目录中。仅需对该仓库启动 Cursor 就足以执行它。","下面的截图显示了结果。多个计算器窗口并非研究人员手动打开的。在项目保持打开状态的过程中，Cursor 不断重新执行重命名的二进制文件，导致随时间出现更多实例。换句话说，这不是一次性启动事件，也不是用户触发的操作。Cursor 在正常操作过程中重复调用了工作区中的可执行内容。","在真实的攻击场景中，计算器可以被攻击者控制的代码替换。","结果是在当前用户权限下执行任意代码，如以下 Sysinternals 进程监视器日志所示：https://learn.microsoft.com/en-us/sysinternals/downloads/procmon （最后验证时间为 2026 年 4 月 30 日，在 Windows 上的 Cursor 3.2.16 版本）。","该漏洞几乎以其简单性令人感到无聊，这也许是最令人担忧的部分。在正常操作过程中，Cursor 会从一个仓库执行攻击者控制的二进制文件，而无需用户任何操作。这样一个直截了当的问题能够在数月内仍未得到修复，应当引起每个当前部署 Cursor 的个人和组织的关注。","大多数协调披露遵循一个熟悉的模式：","这一过程之所以有效，是因为所有相关方有一个共同目标：降低风险。","不幸的是，此案例从未进入风险降低阶段。在七个月过去且没有厂商参与的情况下，有必要质疑这样一个简单且高影响的漏洞是否会得到修复。","安全研究人员了解，修复需要时间，尤其是在大型且快速发展的软件平台中。然而，当几个月过去而没有任何沟通、更新或可见进展时，耐心便难以维持。用户应当得到针对基本威胁的基本保护，而当厂商停止沟通却继续分发受影响的软件时，研究人员最终面临一个令人不快的决定：","我们认为用户应当获得这些信息。完全披露是漏洞披露的“核选项”，仅在其他所有途径都失败的情况下使用。它存在是有原因的：当厂商停止沟通时，用户不应被蒙在鼓里。","最明显的问题也是最简单的问题：为什么这还没有被修复？","该漏洞既不隐蔽，也不难重现，具有直接的执行路径和关键影响。Cursor 的平淡回应引发了更广泛的问题：","安全行业多年来一直鼓励研究人员使用协调披露渠道。这些渠道依赖于响应迅速的分类处理流程以及供应商有能力评估和处理收到的报告。然而，随着 AI 产品的普及，安全发现的数量正在急剧增加。其中许多发现是新的，不能整齐地归入传统的漏洞类别。同时，我们近二十年来依赖的分类处理流程正在迅速失效，因为它们构建的核心假设在新兴的 AI 世界中正在崩溃。","如果披露流程变得不堪重负，行业应该明确说明。研究人员、客户和用户应当获得透明信息。","遗憾的是，随着优先事项问题的出现，这可能并非事实。像许多其他公司一样，Cursor 处于巨大的增长、投资和行业关注的中心。公司正快速扩张，但从外部来看，很难将这种增长与在一个直接的任意代码执行漏洞上缺乏可见进展的情况联系起来。","快速增长带来了在处理安全缺陷时的责任，同时也要求将用户视为有价值的客户，而非试验对象。他们信任生产软件访问源代码、凭据、专有知识产权，并且越来越信任其自主能力。","信任需要问责，而问责需要沟通。当用户、研究人员和披露平台花费数月时间寻求基本状态更新却没有成功时，这种问责变得难以看到或相信。","此次披露不仅涉及名为 git.exe 的单个可执行文件，还涉及软件中的信任问题。AI 公司经常要求用户授予前所未有的访问权限，包括代码、存储库、终端、机密信息以及越来越模糊建议与行动界限的工作流程。","行业的说辞是，这些系统值得信任，因为它们提高了生产力，但历史一再告诉我们，不应仅因为某物有用就给予信任。信任应通过行为来赢得。这种行为体现在公司如何回应安全报告、如何与受影响的用户沟通以及如何优先处理修复工作。","当简单明了的漏洞在几个月内未得到解决且没有有意义的沟通时，用户被迫重新评估对这种信任的假设。","像许多安全研究团队一样，Mindgard 倾向于协调披露。目标永远是先保障安全，其次才是公关。","但协调披露只有在存在协调时才有效。初次披露七个月后，我们仍未看到任何迹象表明用户得到了保护、修复工作正在进行，或受影响的组织已获知情况。而此时，隐瞒信息已不再服务于用户，而是服务于沉默。","出于这个原因，Mindgard 正在发布此漏洞的完整细节。使用 Cursor 的组织理应有机会评估自身暴露风险、实施补偿性控制，并就其安全态势做出知情决策。","用户安全必须放在首位，即使披露变得令人不适。","尤其是在披露变得令人不适的时候。","看看 Mindgard 如何在您的 AI 代理和系统中暴露和修复可被利用的 AI 风险。","Mindgard 是领先的 AI 安全解决方案提供商，帮助企业发现、评估并防御其 AI 系统。Mindgard 从兰开斯特大学十多年 AI 安全研究中独立出来，总部设在波士顿和伦敦，将 AI 红队：https://mindgard.ai/blog/what-is-ai-red-teaming 与进攻性安全专业知识及 AI 研究结合起来，以在攻击者之前识别 AI 模型、代理和应用中的可利用漏洞。"],"translationStatus":"translated","bodyOrigin":"source-page","editorial":{"summary":"Mindgard 披露，Windows 用户用 Cursor 打开根目录含恶意 git.exe 的仓库后，IDE 会在无点击、提示或批准的情况下自动执行该文件，形成任意代码执行风险。","background":"材料称，问题源于 Cursor 加载项目后会在包括当前工作区在内的多个位置查找 Git 可执行文件。Mindgard 表示其在七个月内多次报告，但截至披露时仍未修复。","viewpoint":"Aioga 判断，该问题的关键并非复杂利用链，而是开发工具对工作区内可执行文件的自动信任。由于打开仓库本身即可触发，来源不明的项目可能成为直接攻击入口。","implications":"这可能使钓鱼仓库、被篡改的项目副本或不可信代码包危及 Windows 开发环境。材料还称执行会按一定节奏重复发生，值得关注其对凭据、源码及本地资源的潜在影响。","nextStep":"在官方修复状态得到确认前，Windows 用户应避免直接用 Cursor 打开不可信仓库；可按材料建议使用 AppLocker 阻止工作区中的 git.exe 执行，或先在隔离虚拟机中检查。","evidenceRefs":["title","summary","articleBody","source"],"status":"published","aiGenerated":true,"autoApproved":true,"generatedBy":"aioga-editorial:gpt-5.6-sol","reviewedBy":"aioga-editorial-review:gpt-5.6-sol","generatedAt":"2026-07-22T17:14:01.762Z","sourceHash":"58fc81b33cbf7be4","review":{"approved":true,"groundedness":95,"clarity":92,"duplicationRisk":24,"blockingIssues":[],"notes":["“钓鱼仓库、被篡改的项目副本或不可信代码包”以及对“凭据、源码及本地资源”的影响属于基于任意代码执行风险的合理推演，候选内容已使用“可能”“潜在影响”等限定语，未冒充来源中的已证实事件。","“Aioga 判断”明确标示为观点，且与材料所述触发机制一致。"]},"validation":{"passed":true,"mode":"ai-auto","revisions":0,"checks":["schema","length","source-attribution","low-source-overlap","no-html","independent-ai-review"]}},"tags":["行业动态","Hacker News 热门（buzzing.cc 中文翻译）"],"translations":{"zh-CN":{"title":"Cursor IDE 0day 漏洞：打开恶意仓库即可自动执行任意代码","summary":"安全公司 Mindgard 于 2025 年 12 月 15 日发现 Cursor IDE 存在严重 0day 漏洞。当用户在 Windows 上打开包含恶意 `git.exe` 的仓库时，Cursor 会自动执行该文件，无需任何用户交互。漏洞源于 Cursor 在加载项目时会在包括工作区在内的多个位置搜索 Git 二进制文件。Mindgard 在 7 个月内多次报告，Cursor CISO 虽确认但因内部自动化故障导致流程中断，至今已发布 70 多个新版本仍未修复。临时缓解措施包括使用 AppLocker 阻止从工作区目录执行该文件名，或在隔离虚拟机中打开不受信任的仓库。","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"Cursor IDE 0day 漏洞：打开恶意仓库即可自动执行任意代码 - Aioga AI资讯","description":"安全公司 Mindgard 于 2025 年 12 月 15 日发现 Cursor IDE 存在严重 0day 漏洞。当用户在 Windows 上打开包含恶意 `git.exe` 的仓库时，Cursor 会自动执行该文件，无需任何用户交互。漏洞源于 Cursor 在加载项目时会在包括工作区在内的多个位置搜索 Git 二进制文件。Mindgard 在 7 个月","url":"https://www.aioga.com/news/cmrl6xukw00ogbi7hnn35vq0v/"},"en":{"title":"Cursor IDE 0day vulnerability: Opening a malicious repository automatically executes arbitrary code","summary":"Security company Mindgard discovered a severe 0-day vulnerability in the Cursor IDE on December 15, 2025. When a user opens a repository containing malicious 'git.exe' on Windows, Cursor automatically executes the file without any user interaction. The vulnerability originated from Cursor, when loading the project, searching for Git binaries from multiple locations, including the workspace. Mindgard reported multiple times within seven months; although the Cursor CISO confirmed process disruptions due to internal automation failures, more than 70 new versions have been released and remain unresolved. Temporary mitigation measures include using AppLocker to block the filename from being executed from the workspace directory, or opening untrusted repositories in isolated virtual machines.","category":"Industry","source":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"Cursor IDE 0day vulnerability: Opening a malicious repository automatically executes arbitrary code - Aioga AI News","description":"Security company Mindgard discovered a severe 0-day vulnerability in the Cursor IDE on December 15, 2025. When a user opens a repository containing malicious 'git.exe' on Windows, ","url":"https://www.aioga.com/en/news/cmrl6xukw00ogbi7hnn35vq0v/","contentTranslated":true,"sourceHash":"b2f0756987a95382","translatedAt":"2026-07-19T11:50:58.971Z"},"ja":{"title":"カーソルIDE 0day脆弱性:悪意のあるリポジトリを開くと任意のコードが自動的に実行されます","summary":"セキュリティ企業のMindgardは、2025年12月15日にCursor IDEに深刻な0日脆弱性を発見しました。 ユーザーがWindows上で悪意のある「git.exe」を含むリポジトリを開くと、Cursorはユーザーの操作なしに自動的にファイルを実行します。 この脆弱性は、プロジェクトを読み込む際にCursorが複数の場所(ワークスペースを含む)からGitバイナリを検索した際に発生しました。 Mindgardは7か月間に複数回報告しました。カーソルCISOは内部自動化の失敗によるプロセスの混乱を確認しましたが、70以上の新バージョンがリリースされ、未解決のままです。 一時的な緩和策としては、AppLockerを使ってワークスペースディレクトリからファイル名の実行をブロックしたり、信頼できないリポジトリを孤立した仮想マシンで開くことなどがあります。","category":"業界動向","source":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"カーソルIDE 0day脆弱性:悪意のあるリポジトリを開くと任意のコードが自動的に実行されます - Aioga AIニュース","description":"セキュリティ企業のMindgardは、2025年12月15日にCursor IDEに深刻な0日脆弱性を発見しました。 ユーザーがWindows上で悪意のある「git.exe」を含むリポジトリを開くと、Cursorはユーザーの操作なしに自動的にファイルを実行します。 この脆弱性は、プロジェクトを読み込む際にCursorが複数の場所(ワークスペースを含む)からG","url":"https://www.aioga.com/ja/news/cmrl6xukw00ogbi7hnn35vq0v/","contentTranslated":true,"sourceHash":"b2f0756987a95382","translatedAt":"2026-07-19T11:50:59.778Z"},"ko":{"title":"커서 IDE 0day 취약점: 악성 저장소를 열면 임의의 코드가 자동으로 실행됩니다","summary":"보안 회사 Mindgard는 2025년 12월 15일 Cursor IDE에서 심각한 0-day 취약점을 발견했습니다. 사용자가 Windows에서 악성 'git.exe'가 포함된 저장소를 열면, Cursor는 사용자의 개입 없이 자동으로 파일을 실행합니다. 이 취약점은 프로젝트를 로드할 때 작업 공간 등 여러 위치에서 Git 바이너리를 검색하는 커서에서 발생했습니다. Mindgard는 7개월 동안 여러 차례 보고했습니다; Cursor CISO는 내부 자동화 실패로 인한 프로세스 중단을 확인했지만, 70개 이상의 새로운 버전이 출시되었고 아직 해결되지 않았습니다. 임시 완화 조치로는 AppLocker를 사용해 작업 공간 디렉터리에서 파일 이름이 실행되지 않도록 차단하거나, 격리된 가상 머신에서 신뢰할 수 없는 저장소를 여는 것이 있습니다.","category":"업계 동향","source":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"커서 IDE 0day 취약점: 악성 저장소를 열면 임의의 코드가 자동으로 실행됩니다 - Aioga AI 뉴스","description":"보안 회사 Mindgard는 2025년 12월 15일 Cursor IDE에서 심각한 0-day 취약점을 발견했습니다. 사용자가 Windows에서 악성 'git.exe'가 포함된 저장소를 열면, Cursor는 사용자의 개입 없이 자동으로 파일을 실행합니다. 이 취약점은 프로젝트를 로드할 때 작업 공간 등 여러 위치에서 Gi","url":"https://www.aioga.com/ko/news/cmrl6xukw00ogbi7hnn35vq0v/","contentTranslated":true,"sourceHash":"b2f0756987a95382","translatedAt":"2026-07-19T11:50:59.297Z"},"es":{"title":"Vulnerabilidad del cursor IDE 0day: Abrir un repositorio malicioso ejecuta automáticamente código arbitrario","summary":"La empresa de seguridad Mindgard descubrió una grave vulnerabilidad 0-day en el IDE de Cursor el 15 de diciembre de 2025. Cuando un usuario abre un repositorio que contiene 'git.exe' maliciosos en Windows, Cursor ejecuta automáticamente el archivo sin ninguna interacción del usuario. La vulnerabilidad se originó en Cursor, al cargar el proyecto, buscar binarios Git desde múltiples ubicaciones, incluido el espacio de trabajo. Mindgard informó varias veces en siete meses; aunque el CISO de Cursor confirmó interrupciones en los procesos debido a fallos internos de automatización, se han lanzado más de 70 nuevas versiones que siguen sin resolverse. Las medidas temporales de mitigación incluyen usar AppLocker para bloquear la ejecución del nombre del archivo desde el directorio del espacio de trabajo, o abrir repositorios no confiables en máquinas virtuales aisladas.","category":"Industria","source":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"Vulnerabilidad del cursor IDE 0day: Abrir un repositorio malicioso ejecuta automáticamente código arbitrario - Aioga Noticias de IA","description":"La empresa de seguridad Mindgard descubrió una grave vulnerabilidad 0-day en el IDE de Cursor el 15 de diciembre de 2025. Cuando un usuario abre un repositorio que contiene 'git.ex","url":"https://www.aioga.com/es/news/cmrl6xukw00ogbi7hnn35vq0v/","contentTranslated":true,"sourceHash":"b2f0756987a95382","translatedAt":"2026-07-19T11:50:59.484Z"},"fr":{"title":"Vulnérabilité de l’IDE du curseur 0day : L’ouverture d’un dépôt malveillant exécute automatiquement un code arbitraire","summary":"La société de sécurité Mindgard a découvert une vulnérabilité grave 0-day dans l’IDE Cursor le 15 décembre 2025. Lorsqu’un utilisateur ouvre un dépôt contenant des « git.exe » malveillants sous Windows, Cursor exécute automatiquement le fichier sans aucune interaction utilisateur. La vulnérabilité provient de Cursor, lors du chargement du projet, qui recherchait des binaires Git à plusieurs endroits, y compris dans l’espace de travail. Mindgard a signalé plusieurs fois en sept mois ; bien que le CISO de Cursor ait confirmé des perturbations de processus dues à des défaillances d’automatisation interne, plus de 70 nouvelles versions ont été publiées et restent non résolues. Les mesures temporaires d’atténuation incluent l’utilisation d’AppLocker pour bloquer l’exécution du nom de fichier depuis le répertoire de l’espace de travail, ou l’ouverture de dépôts non fiables dans des machines virtuelles isolées.","category":"Industrie","source":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"Vulnérabilité de l’IDE du curseur 0day : L’ouverture d’un dépôt malveillant exécute automatiquement un code arbitraire - Aioga Actualités IA","description":"La société de sécurité Mindgard a découvert une vulnérabilité grave 0-day dans l’IDE Cursor le 15 décembre 2025. Lorsqu’un utilisateur ouvre un dépôt contenant des « git.exe » malv","url":"https://www.aioga.com/fr/news/cmrl6xukw00ogbi7hnn35vq0v/","contentTranslated":true,"sourceHash":"b2f0756987a95382","translatedAt":"2026-07-19T11:50:59.448Z"},"de":{"title":"Cursor-IDE 0-Day-Schwachstelle: Das Öffnen eines bösartigen Repositorys führt automatisch beliebigen Code aus","summary":"Das Sicherheitsunternehmen Mindgard entdeckte am 15. Dezember 2025 eine schwere 0-Tage-Schwachstelle in der Cursor-IDE. Wenn ein Benutzer ein Repository mit bösartigen 'git.exe' unter Windows öffnet, führt Cursor die Datei automatisch ohne Benutzerinteraktion aus. Die Schwachstelle entstand durch Cursor, der beim Laden des Projekts nach Git-Binärdateien von mehreren Standorten, einschließlich des Arbeitsbereichs, suchte. Mindgard berichtete innerhalb von sieben Monaten mehrfach; obwohl der Cursor-CISO Prozessstörungen durch interne Automatisierungsfehler bestätigte, wurden mehr als 70 neue Versionen veröffentlicht und sind weiterhin ungelöst. Temporäre Minderungsmaßnahmen umfassen die Verwendung von AppLocker, um den Dateinamen daran zu hindern, aus dem Workspace-Verzeichnis ausgeführt zu werden, oder das Öffnen nicht vertrauenswürdiger Repositories in isolierten virtuellen Maschinen.","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"Cursor-IDE 0-Day-Schwachstelle: Das Öffnen eines bösartigen Repositorys führt automatisch beliebigen Code aus - Aioga KI-News","description":"Das Sicherheitsunternehmen Mindgard entdeckte am 15. Dezember 2025 eine schwere 0-Tage-Schwachstelle in der Cursor-IDE. Wenn ein Benutzer ein Repository mit bösartigen 'git.exe' un","url":"https://www.aioga.com/de/news/cmrl6xukw00ogbi7hnn35vq0v/","contentTranslated":true,"sourceHash":"b2f0756987a95382","translatedAt":"2026-07-19T11:51:02.772Z"},"pt-BR":{"title":"Vulnerabilidade do cursor IDE 0day: Abrir um repositório malicioso executa automaticamente código arbitrário","summary":"A empresa de segurança Mindgard descobriu uma grave vulnerabilidade 0-day no IDE do Cursor em 15 de dezembro de 2025. Quando um usuário abre um repositório contendo 'git.exe' maliciosas no Windows, o Cursor executa automaticamente o arquivo sem qualquer interação do usuário. A vulnerabilidade se originou do Cursor, ao carregar o projeto, buscar binários Git em múltiplos locais, incluindo o espaço de trabalho. A Mindgard reportou várias vezes em sete meses; embora o CISO do Cursor tenha confirmado interrupções de processos devido a falhas internas de automação, mais de 70 novas versões foram lançadas e permanecem sem solução. Medidas temporárias de mitigação incluem o uso do AppLocker para bloquear a execução do nome do arquivo a partir do diretório do workspace, ou abrir repositórios não confiáveis em máquinas virtuais isoladas.","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"Vulnerabilidade do cursor IDE 0day: Abrir um repositório malicioso executa automaticamente código arbitrário - Aioga Notícias de IA","description":"A empresa de segurança Mindgard descobriu uma grave vulnerabilidade 0-day no IDE do Cursor em 15 de dezembro de 2025. Quando um usuário abre um repositório contendo 'git.exe' malic","url":"https://www.aioga.com/pt-BR/news/cmrl6xukw00ogbi7hnn35vq0v/","contentTranslated":true,"sourceHash":"b2f0756987a95382","translatedAt":"2026-07-19T11:51:04.065Z"},"ru":{"title":"Уязвимость Cursor IDE 0day: Открытие вредоносного репозитория автоматически запускает произвольный код","summary":"Охранная компания Mindgard обнаружила серьёзную уязвимость 0-дневной в IDE Cursor 15 декабря 2025 года. Когда пользователь открывает репозиторий с вредоносным 'git.exe' в Windows, Cursor автоматически запускает файл без какого-либо взаимодействия пользователя. Уязвимость возникла из-за Cursor при загрузке проекта, при поиске бинарных файлов Git из нескольких точек, включая рабочее пространство. Mindgard докладывал несколько раз в течение семи месяцев; хотя CISO Cursor подтвердил сбои в процессе из-за внутренних сбоев автоматизации, было выпущено более 70 новых версий, которые остаются нерешёнными. Временные меры предотвращения включают использование AppLocker для блокировки файла из каталога рабочего пространства или открытие ненадёжных репозиториев в изолированных виртуальных машинах.","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"Уязвимость Cursor IDE 0day: Открытие вредоносного репозитория автоматически запускает произвольный код - Aioga Новости ИИ","description":"Охранная компания Mindgard обнаружила серьёзную уязвимость 0-дневной в IDE Cursor 15 декабря 2025 года. Когда пользователь открывает репозиторий с вредоносным 'git.exe' в Windows, ","url":"https://www.aioga.com/ru/news/cmrl6xukw00ogbi7hnn35vq0v/","contentTranslated":true,"sourceHash":"b2f0756987a95382","translatedAt":"2026-07-19T11:51:04.078Z"},"ar":{"title":"ثغرة في بيئة تطوير المؤشر 0day: فتح مستودع خبيث يؤدي تلقائيا إلى تنفيذ كود عشوائي","summary":"اكتشفت شركة الأمن Mindgard ثغرة خطيرة في يوم صفر في بيئة تطوير Cursor IDE في 15 ديسمبر 2025. عندما يفتح المستخدم مستودعا يحتوي على 'git.exe' خبيثة على ويندوز، يقوم المؤشر بتنفيذ الملف تلقائيا دون أي تفاعل من المستخدم. نشأت الثغرة من Cursor، عند تحميل المشروع، حيث كان يبحث عن ملفات Git الثنائية من عدة مواقع، بما في ذلك مساحة العمل. أبلغت Mindgard عن عدة مرات خلال سبعة أشهر؛ على الرغم من أن CISO في Cursor أكدت اضطرابات العمليات بسبب أعطال الأتمتة الداخلية، إلا أن أكثر من 70 نسخة جديدة تم إصدارها ولا تزال غير محلولة. تشمل التدابير المؤقتة للتخفيف استخدام AppLocker لمنع تنفيذ اسم الملف من مجلد workspace، أو فتح مستودعات غير موثوقة في الآلات الافتراضية المعزولة.","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"ثغرة في بيئة تطوير المؤشر 0day: فتح مستودع خبيث يؤدي تلقائيا إلى تنفيذ كود عشوائي - Aioga أخبار الذكاء الاصطناعي","description":"اكتشفت شركة الأمن Mindgard ثغرة خطيرة في يوم صفر في بيئة تطوير Cursor IDE في 15 ديسمبر 2025. عندما يفتح المستخدم مستودعا يحتوي على 'git.exe' خبيثة على ويندوز، يقوم المؤشر بتنفيذ ال","url":"https://www.aioga.com/ar/news/cmrl6xukw00ogbi7hnn35vq0v/","contentTranslated":true,"sourceHash":"b2f0756987a95382","translatedAt":"2026-07-19T11:51:03.789Z"},"hi":{"title":"कर्सर आईडीई 0दिन भेद्यता: एक दुर्भावनापूर्ण रिपॉजिटरी खोलना स्वचालित रूप से मनमाना कोड निष्पादित करता है","summary":"सुरक्षा कंपनी माइंडगार्ड ने 0 दिसंबर, 15 को कर्सर आईडीई में 2025-दिन की गंभीर भेद्यता की खोज की। जब कोई उपयोगकर्ता विंडोज पर दुर्भावनापूर्ण 'git.exe' वाला रिपॉजिटरी खोलता है, तो कर्सर स्वचालित रूप से किसी भी उपयोगकर्ता इंटरैक्शन के बिना फ़ाइल को निष्पादित करता है। भेद्यता कर्सर से उत्पन्न हुई, प्रोजेक्ट लोड करते समय, कार्यक्षेत्र सहित कई स्थानों से गिट बायनेरिज़ की खोज करना। माइंडगार्ड ने सात महीनों के भीतर कई बार रिपोर्ट की; हालांकि कर्सर सीआईएसओ ने आंतरिक स्वचालन विफलताओं के कारण प्रक्रिया व्यवधानों की पुष्टि की, 70 से अधिक नए संस्करण जारी किए गए हैं और अनसुलझे हैं। अस्थायी शमन उपायों में फ़ाइल नाम को कार्यस्थान निर्देशिका से निष्पादित होने से ब्लॉक करने के लिए AppLocker का उपयोग करना, या अलग-अलग वर्चुअल मशीनों में अविश्वसनीय रिपॉजिटरी खोलना शामिल है।","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"कर्सर आईडीई 0दिन भेद्यता: एक दुर्भावनापूर्ण रिपॉजिटरी खोलना स्वचालित रूप से मनमाना कोड निष्पादित करता है - Aioga AI समाचार","description":"सुरक्षा कंपनी माइंडगार्ड ने 0 दिसंबर, 15 को कर्सर आईडीई में 2025-दिन की गंभीर भेद्यता की खोज की। जब कोई उपयोगकर्ता विंडोज पर दुर्भावनापूर्ण 'git.exe' वाला रिपॉजिटरी खोलता है, तो कर","url":"https://www.aioga.com/hi/news/cmrl6xukw00ogbi7hnn35vq0v/","contentTranslated":true,"sourceHash":"b2f0756987a95382","translatedAt":"2026-07-19T11:51:03.996Z"},"it":{"title":"Vulnerabilità Cursor IDE 0day: Aprire un repository malevolo esegue automaticamente codice arbitrario","summary":"La società di sicurezza Mindgard ha scoperto una grave vulnerabilità 0-day nell'IDE di Cursor il 15 dicembre 2025. Quando un utente apre un repository contenente 'git.exe' malevoli su Windows, Cursor esegue automaticamente il file senza alcuna interazione dell'utente. La vulnerabilità ha avuto origine da Cursor, quando si caricava il progetto, la ricerca di binari Git da più località, incluso lo spazio di lavoro. Mindgard ha riportato più volte in sette mesi; sebbene il CISO di Cursor abbia confermato interruzioni di processo dovute a guasti interni di automazione, sono state rilasciate più di 70 nuove versioni che rimangono irrisolte. Le misure temporanee di mitigazione includono l'uso di AppLocker per bloccare l'esecuzione del nome file dalla directory dello spazio di lavoro, o l'apertura di repository non affidabili in macchine virtuali isolate.","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"Vulnerabilità Cursor IDE 0day: Aprire un repository malevolo esegue automaticamente codice arbitrario - Aioga Notizie IA","description":"La società di sicurezza Mindgard ha scoperto una grave vulnerabilità 0-day nell'IDE di Cursor il 15 dicembre 2025. Quando un utente apre un repository contenente 'git.exe' malevoli","url":"https://www.aioga.com/it/news/cmrl6xukw00ogbi7hnn35vq0v/","contentTranslated":true,"sourceHash":"b2f0756987a95382","translatedAt":"2026-07-19T11:51:04.591Z"},"nl":{"title":"Cursor IDE 0day-kwetsbaarheid: Het openen van een kwaadaardige repository voert automatisch willekeurige code uit","summary":"Beveiligingsbedrijf Mindgard ontdekte op 15 december 2025 een ernstige 0-dag-kwetsbaarheid in de Cursor IDE. Wanneer een gebruiker een repository opent met kwaadaardige 'git.exe' op Windows, voert Cursor het bestand automatisch uit zonder enige gebruikersinteractie. De kwetsbaarheid ontstond bij Cursor, die bij het laden van het project zocht naar Git-binaries vanaf meerdere locaties, inclusief de werkruimte. Mindgard rapporteerde meerdere keren binnen zeven maanden; hoewel de Cursor CISO procesverstoringen door interne automatiseringstoringen bevestigde, zijn er meer dan 70 nieuwe versies uitgebracht die nog steeds niet zijn opgelost. Tijdelijke mitigatiemaatregelen omvatten het gebruik van AppLocker om te blokkeren dat de bestandsnaam uit de workspace-map wordt uitgevoerd, of het openen van onbetrouwbare repositories in geïsoleerde virtuele machines.","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"Cursor IDE 0day-kwetsbaarheid: Het openen van een kwaadaardige repository voert automatisch willekeurige code uit - Aioga AI-nieuws","description":"Beveiligingsbedrijf Mindgard ontdekte op 15 december 2025 een ernstige 0-dag-kwetsbaarheid in de Cursor IDE. Wanneer een gebruiker een repository opent met kwaadaardige 'git.exe' o","url":"https://www.aioga.com/nl/news/cmrl6xukw00ogbi7hnn35vq0v/","contentTranslated":true,"sourceHash":"b2f0756987a95382","translatedAt":"2026-07-19T11:51:02.810Z"},"tr":{"title":"Cursor IDE 0day açığlığı: Kötü niyetli bir depo açılması otomatik olarak rastgele kodu çalıştırır","summary":"Güvenlik şirketi Mindgard, 15 Aralık 2025'te Cursor IDE'de ciddi bir 0-günlük güvenlik açığı keşfetti. Bir kullanıcı Windows'ta kötü amaçlı 'git.exe' içeren bir depoyu açtığında, Cursor dosyayı otomatik olarak herhangi bir kullanıcı etkileşimi olmadan çalıştırır. Güvenlik açığı, projeyi yüklerken, çalışma alanı da dahil olmak üzere birden fazla konumdan Git ikili ararken Cursor'dan kaynaklanıyordu. Mindgard yedi ay içinde defalarca rapor verdi; Cursor CISO'su dahili otomasyon hataları nedeniyle süreç kesintilerini doğrulasa da, 70'ten fazla yeni sürüm yayımlandı ve hâlâ çözülmemiş. Geçici azaltma önlemleri arasında, dosya adının çalışma alanı dizininden çalıştırılmasını engellemek için AppLocker kullanmak veya izole sanal makinelerde güvenilmeyen depoları açmak yer alır.","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"Cursor IDE 0day açığlığı: Kötü niyetli bir depo açılması otomatik olarak rastgele kodu çalıştırır - Aioga AI Haberleri","description":"Güvenlik şirketi Mindgard, 15 Aralık 2025'te Cursor IDE'de ciddi bir 0-günlük güvenlik açığı keşfetti. Bir kullanıcı Windows'ta kötü amaçlı 'git.exe' içeren bir depoyu açtığında, C","url":"https://www.aioga.com/tr/news/cmrl6xukw00ogbi7hnn35vq0v/","contentTranslated":true,"sourceHash":"b2f0756987a95382","translatedAt":"2026-07-19T11:51:03.007Z"},"vi":{"title":"Lỗ hổng Cursor IDE 0day: Mở kho lưu trữ độc hại sẽ tự động thực thi mã tùy ý","summary":"Công ty bảo mật Mindgard đã phát hiện ra lỗ hổng 0 ngày nghiêm trọng trong Cursor IDE vào ngày 15 tháng 12 năm 2025. Khi người dùng mở kho lưu trữ chứa 'git.exe' độc hại trên Windows, Con trỏ sẽ tự động thực thi tệp mà không cần bất kỳ tương tác nào của người dùng. Lỗ hổng bắt nguồn từ Cursor, khi tải dự án, tìm kiếm các tệp nhị phân Git từ nhiều vị trí, bao gồm cả không gian làm việc. Mindgard đã báo cáo nhiều lần trong vòng bảy tháng; mặc dù CISO của Cursor xác nhận sự gián đoạn quy trình do lỗi tự động hóa nội bộ, hơn 70 phiên bản mới đã được phát hành và vẫn chưa được giải quyết. Các biện pháp giảm thiểu tạm thời bao gồm sử dụng AppLocker để chặn tên tệp được thực thi từ thư mục không gian làm việc hoặc mở các kho lưu trữ không đáng tin cậy trong các máy ảo bị cô lập.","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"Lỗ hổng Cursor IDE 0day: Mở kho lưu trữ độc hại sẽ tự động thực thi mã tùy ý - Tin tức AI Aioga","description":"Công ty bảo mật Mindgard đã phát hiện ra lỗ hổng 0 ngày nghiêm trọng trong Cursor IDE vào ngày 15 tháng 12 năm 2025. Khi người dùng mở kho lưu trữ chứa 'git.exe' độc hại trên Windo","url":"https://www.aioga.com/vi/news/cmrl6xukw00ogbi7hnn35vq0v/","contentTranslated":true,"sourceHash":"b2f0756987a95382","translatedAt":"2026-07-19T11:51:02.668Z"},"id":{"title":"Kerentanan Kursor IDE 0day: Membuka repositori berbahaya secara otomatis mengeksekusi kode arbitrer","summary":"Perusahaan keamanan Mindgard menemukan kerentanan 0 hari yang parah di Cursor IDE pada 15 Desember 2025. Saat pengguna membuka repositori yang berisi 'git.exe' berbahaya di Windows, Kursor secara otomatis mengeksekusi file tanpa interaksi pengguna apa pun. Kerentanan berasal dari Cursor, saat memuat proyek, mencari biner Git dari beberapa lokasi, termasuk ruang kerja. Mindgard melaporkan beberapa kali dalam waktu tujuh bulan; meskipun CISO Cursor mengkonfirmasi gangguan proses karena kegagalan otomatisasi internal, lebih dari 70 versi baru telah dirilis dan tetap belum terselesaikan. Langkah-langkah mitigasi sementara termasuk menggunakan AppLocker untuk memblokir nama file agar tidak dieksekusi dari direktori ruang kerja, atau membuka repositori yang tidak tepercaya di komputer virtual yang terisolasi.","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"Kerentanan Kursor IDE 0day: Membuka repositori berbahaya secara otomatis mengeksekusi kode arbitrer - Berita AI Aioga","description":"Perusahaan keamanan Mindgard menemukan kerentanan 0 hari yang parah di Cursor IDE pada 15 Desember 2025. Saat pengguna membuka repositori yang berisi 'git.exe' berbahaya di Windows","url":"https://www.aioga.com/id/news/cmrl6xukw00ogbi7hnn35vq0v/","contentTranslated":true,"sourceHash":"b2f0756987a95382","translatedAt":"2026-07-19T11:51:03.832Z"},"th":{"title":"ช่องโหว่ Cursor IDE 0day: การเปิดที่เก็บที่เป็นอันตรายจะรันโค้ดโดยอําเภอใจโดยอัตโนมัติ","summary":"บริษัทรักษาความปลอดภัย Mindgard ค้นพบช่องโหว่ 0 วันที่รุนแรงใน Cursor IDE เมื่อวันที่ 15 ธันวาคม 2025 เมื่อผู้ใช้เปิดที่เก็บที่มี 'git.exe' ที่เป็นอันตรายบน Windows เคอร์เซอร์จะเรียกใช้ไฟล์โดยอัตโนมัติโดยไม่ต้องโต้ตอบกับผู้ใช้ ช่องโหว่นี้เกิดจาก Cursor เมื่อโหลดโปรเจ็กต์ โดยค้นหาไบนารี Git จากหลายตําแหน่ง รวมถึงพื้นที่ทํางาน Mindgard รายงานหลายครั้งภายในเจ็ดเดือนแม้ว่า Cursor CISO จะยืนยันการหยุดชะงักของกระบวนการเนื่องจากความล้มเหลวของระบบอัตโนมัติภายใน แต่ก็มีการเปิดตัวเวอร์ชันใหม่มากกว่า 70 เวอร์ชันและยังไม่ได้รับการแก้ไข มาตรการบรรเทาผลกระทบชั่วคราวรวมถึงการใช้ AppLocker เพื่อบล็อกชื่อไฟล์ไม่ให้ถูกเรียกใช้จากไดเรกทอรีพื้นที่ทํางาน หรือการเปิดที่เก็บที่ไม่น่าเชื่อถือในเครื่องเสมือนที่แยกจากกัน","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"ช่องโหว่ Cursor IDE 0day: การเปิดที่เก็บที่เป็นอันตรายจะรันโค้ดโดยอําเภอใจโดยอัตโนมัติ - ข่าว AI Aioga","description":"บริษัทรักษาความปลอดภัย Mindgard ค้นพบช่องโหว่ 0 วันที่รุนแรงใน Cursor IDE เมื่อวันที่ 15 ธันวาคม 2025 เมื่อผู้ใช้เปิดที่เก็บที่มี 'git.exe' ที่เป็นอันตรายบน Windows เคอร์เซอร์จะเรี","url":"https://www.aioga.com/th/news/cmrl6xukw00ogbi7hnn35vq0v/","contentTranslated":true,"sourceHash":"b2f0756987a95382","translatedAt":"2026-07-19T11:51:04.185Z"},"pl":{"title":"Podatność 0day w IDE kursora: Otwarcie złośliwego repozytorium automatycznie uruchamia dowolny kod","summary":"Firma zajmująca się bezpieczeństwem Mindgard odkryła poważną lukę 0-day w IDE Cursor 15 grudnia 2025 roku. Gdy użytkownik otwiera repozytorium zawierające złośliwe 'git.exe' w systemie Windows, kursor automatycznie uruchamia plik bez żadnej interakcji użytkownika. Luka pochodziła z Kursora, który podczas ładowania projektu wyszukiwał pliki binarne Git z wielu lokalizacji, w tym z przestrzeni roboczej. Mindgard raportował wielokrotnie w ciągu siedmiu miesięcy; chociaż CISO Kursora potwierdziło zakłócenia procesów spowodowane awariami automatyzacji wewnętrznej, wydano ponad 70 nowych wersji i pozostają nierozwiązane. Tymczasowe środki łagodzące obejmują użycie AppLocker do zablokowania nazwy pliku przed wykonywaniem z katalogu workspace lub otwieranie niezaufanych repozytoriów w izolowanych maszynach wirtualnych.","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"Podatność 0day w IDE kursora: Otwarcie złośliwego repozytorium automatycznie uruchamia dowolny kod - Aioga Wiadomości AI","description":"Firma zajmująca się bezpieczeństwem Mindgard odkryła poważną lukę 0-day w IDE Cursor 15 grudnia 2025 roku. Gdy użytkownik otwiera repozytorium zawierające złośliwe 'git.exe' w syst","url":"https://www.aioga.com/pl/news/cmrl6xukw00ogbi7hnn35vq0v/","contentTranslated":true,"sourceHash":"b2f0756987a95382","translatedAt":"2026-07-19T11:51:04.918Z"}}}}