Description
Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and opens a crafted repository, Cursor automatically resolves and executes the workspace-resident git.exe during IDE startup and on a recurring timed cadence without any user interaction, running the malicious binary under the privileges of the current user.
Published: 2026-07-17
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Cursor for Windows version 3.2.16 contains a binary planting flaw that lets a remote attacker execute arbitrary code by placing a malicious git.exe file in the repository root. When a developer clones or opens the crafted repository, the IDE starts up and repeatedly runs the workspace‑resident git.exe without user interaction, giving the malicious binary the same privileges as the current user. This flaw maps to CWE‑426 – Untrusted Search Path – and results in full remote code exploitation for the user running the IDE.

Affected Systems

The affected vendor is Anysphere, Inc. and the product is Cursor for Windows. Targeted is the 3.2.16 release of the software.

Risk and Exploitability

The CVSS score of 8.7 places the vulnerability in the high severity band, while the EPSS score of less than 1% indicates that exploitation events are rare but still plausible. The vulnerability is not listed in the CISA KEV catalog. An attacker can trigger the flaw by uploading a crafted repository containing a malicious git.exe to any repository that will be cloned by a developer. Once the repository is cloned or opened, Cursor automatically resolves and executes the bundled git.exe at startup and on a recurring cadence, allowing the attacker to run arbitrary commands under the user’s privileges. The risk therefore remains significant, especially in environments where developers routinely clone external repositories without prior inspection.

Generated by OpenCVE AI on July 31, 2026 at 00:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Cursor for Windows to the latest available release that removes the binary planting flaw.
  • Configure the IDE to disable automatic execution of workspace‑resident git executables, or enforce a whitelist of approved binaries.
  • Implement repository content checks or an antivirus scan that flags or blocks suspicious binaries such as git.exe before the repository is cloned or opened.

Generated by OpenCVE AI on July 31, 2026 at 00:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:anysphere:cursor:3.2.16:*:*:*:*:*:*:*

Fri, 17 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Anysphere
Anysphere cursor
Vendors & Products Anysphere
Anysphere cursor

Fri, 17 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and opens a crafted repository, Cursor automatically resolves and executes the workspace-resident git.exe during IDE startup and on a recurring timed cadence without any user interaction, running the malicious binary under the privileges of the current user.
Title Cursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace
Weaknesses CWE-426
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Anysphere Cursor
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-28T01:49:58.652Z

Reserved: 2026-07-15T15:45:44.601Z

Link: CVE-2026-63093

cve-icon Vulnrichment

Updated: 2026-07-17T15:08:54.063Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T00:30:18Z

Weaknesses