CVE-2026-63093: Cursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace
Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and opens a crafted repository, Cursor automatically resolves and executes the workspace-resident git.exe during IDE startup and on a recurring timed cadence without any user interaction, running the malicious binary under the privileges of the current user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63093?
CVE-2026-63093 has a severity rating of 8.8, classified as high risk.
How do I fix CVE-2026-63093?
To mitigate CVE-2026-63093, ensure that you do not clone repositories from untrusted sources and regularly update Cursor for Windows.
What type of vulnerability is CVE-2026-63093?
CVE-2026-63093 is a binary planting vulnerability that allows for remote code execution.
Who is affected by CVE-2026-63093?
Any user of Cursor for Windows version 3.2.16 is potentially affected by CVE-2026-63093.
What can attackers do with CVE-2026-63093?
Attackers can exploit CVE-2026-63093 to execute arbitrary code on a victim's machine by placing a malicious git.exe in a cloned repository.