• News/
  • https://www.bleepingcomputer.com/news/security/cursor-ai-editor-lets-repos-autorun-malicious-code-on-devices/

Cursor AI editor lets repos “autorun” malicious code on devices

BleepingComputer
·
Bill Toulas
·
Published Sep 10, 2025
·
Updated

A weakness in the Cursor code editor exposes developers to the risk of automatically executing tasks in a malicious repository as soon as it’s opened. Threat actors can exploit the flaw to drop malware, hijack developer environments, or steal credentials and API tokens, without developers having to execute any commands. Cursor is an AI-powered Integrated Development Environment (IDE) built as a fork of Visual Studio Code (VS Code) that has deep integration of mainstream AI assistants like GPT-4 and Claude for software development tasks. It is one of the fastest-growing AI-coding tools, currently used by one million users to generate more than a billion lines of code every day. Researchers at Oasis Security, a company that provides a management and security solution for non-human identities (NHIs), found that the issue stems from Cursor disabling the Workspace Trust feature from VS Code, which blocks automatic execution of tasks without developers' explicit consent. In the default configuration, Cursor executes tasks immediately after opening a project folder. A threat actor could take advantage of this by adding a malicious .vscode/tasks.json file in a publicly shared repository. "When a user opens such a repository from Cursor, even for simple browsing, arbitrary code can be run in their environment," the researchers at Oasis Security say. "This has the potential to leak sensitive credentials, modify files, or serve as a vector for broader system compromise." VS Code, howev...

Read full article

Affected Software

2 affected components
Cursor Cursor
Microsoft Visual Studio Code
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a vulnerability in the Cursor AI code editor that allows malicious repositories to autorun code on developers' devices.

2

What security implications are discussed?

The article highlights the risk of malware execution and environment hijacking due to the flaw in the Cursor code editor.

3

What products or software are affected?

The affected software includes the Cursor AI code editor and Microsoft Visual Studio Code.

4

Who is at risk from this vulnerability?

Developers using the Cursor AI editor are at risk of having malicious code executed when opening certain repositories.

5

What can developers do to protect themselves from this vulnerability?

Developers should be cautious when opening repositories in Cursor and consider reviewing the code and permissions before execution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203