Cursor IDE Auto-Executes Malicious Code in Poisoned Repos
A serious flaw in the Cursor IDE allows for the automatic execution of malicious code from compromised repositories, despite researchers alerting the developers in December. This vulnerability opens the door for "poisoned repo" attacks, where bad actors can inject harmful code that executes when users interact with the IDE. Given Cursor's popularity among developers, this issue could have widespread implications, potentially compromising countless projects and putting developers' security at risk. The ongoing presence of this bug highlights the urgent need for robust security measures in coding platforms.
Original Source
Read the full article at Darkreading →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.