Dev.to
7/15/2026

The original headline is "Cursor has an unpatched 0-day. It's been 7 months."
Original: Cursor has an unpatched 0-day. It's been 7 months.
Short summary
Mindgard disclosed a Cursor 0-day vulnerability where a malicious git.exe placed in a repository root is automatically executed by Cursor on Windows with no user interaction. The bug was reported December 15, 2025, and remains unpatched seven months and 197+ versions later despite HackerOne confirmation. Mindgard went public after Cursor stopped responding, urging users to isolate untrusted repos and treat the issue as a supply-chain risk affecting 7 million developers and 50,000+ companies.
- •Cursor automatically executes a git.exe file placed in a repo root on Windows — no clicks or prompts required
- •Mindgard reported the bug in Dec 2025; it remains unpatched 7 months and 197+ versions later
- •Mitigations include AppLocker deny rules on enterprise Windows and opening untrusted repos in a VM or sandbox
Generated with AI, which can make mistakes.
Is this a good recommendation for you?

