Microsoft's fifth July update expands agent monitoring, adds offline speech transcription and changes Python environment management.
An attacker can create a malicious repository containing a git.exe in the project root, and Cursor executes it automatically. An unpatched vulnerability in Cursor on Windows can be triggered for code ...
Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to ...