Cursor AI Code Editor Flaw Enables Silent Code Execution via Malicious Repositories

Friday, September 12, 2025 4:49 AM | The Hacker News
A security weakness has been disclosed in the artificial intelligence (AI)-powered code editor Cursor that could trigger code execution when a maliciously crafted repository is opened using the program. The issue stems from the fact that an out-of-the-box security setting is disabled by default, opening the door for attackers to run arbitrary code on users' computers with their privileges. "