CVE-2026-63093 Details
Description
Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and opens a crafted repository, Cursor automatically resolves and executes the workspace-resident git.exe during IDE startup and on a recurring timed cadence without any user interaction, running the malicious binary under the privileges of the current user.
A binary planting vulnerability has been identified in Cursor for Windows, specifically in version 3.2.16. This vulnerability allows remote attackers to execute arbitrary code by placing a malicious git.exe file in the root directory of a repository. When a developer clones and opens this repository, Cursor automatically executes the git.exe file during the IDE's startup process and at regular intervals, without any user interaction. The malicious code runs under the current user's privileges, potentially leading to significant security risks.
As a temporary mitigation, administrators can use AppLocker or Windows App Control policies to block the execution of git.exe from developer workspace directories. For consumer systems, it is recommended to open untrusted repositories in a virtual machine or disposable environment until the vulnerability is patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cursor.com/ | [email protected] | Product |
| https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left | [email protected] | Third Party AdvisoryExploit |
| https://www.vulncheck.com/advisories/cursor-for-windows-rce-via-malicious-git-exe-in-workspace | [email protected] | Third Party AdvisoryExploit |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-426 | Untrusted Search Path | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| anysphere cursor | <= 3.2.16 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 14, 2026 | Initial Analysis | [email protected] |
| Jul 17, 2026 | CVE Modified | CISA-ADP |
| Jul 17, 2026 | New CVE Received | [email protected] |