• News/
  • https://www.bleepingcomputer.com/news/security/the-zero-day-that-couldve-compromised-every-cursor-and-windsurf-user/

The zero-day that could've compromised every Cursor and Windsurf user

BleepingComputer
·
Sponsored by Koi Security
·
Published Jul 11, 2025
·
Updated

A security researcher from Koi Security stumbled upon a critical zero-day buried deep in the infrastructure powering today’s AI coding tools. Had it been exploited, a non-sophisticated attacker could’ve hijacked over 10 million machines with a single stroke. AI coding assistants like Cursor and Windsurf have exploded in popularity, promising supercharged productivity for developers around the world. Behind their sleek interfaces lies a shared foundation: community-built VS Code forks and an open marketplace of extensions that powers the magic. But, with this new wave of developer tooling comes a dangerous blind spot. Dubbed VSXPloit: A single overlooked flaw in OpenVSX - a critical component in the developer supply chain - allowed silent, full-system compromise on any machine running a VS Code fork. One bug. Total control. Let’s dive in. Today’s AI-powered editors heavily rely on extensions to deliver their most basic functionality. Features like syntax highlighting, linting, and debugging aren’t hardcoded into the editor - they are provided by extensions. Each of these extensions runs with full privileges on the developer’s machine. This in turn means that a single compromised extension can lead to full machine takeover of anyone who installs it.

This exact nightmare scenario is what security researcher Oren Yomtov from Koi Security, a company providing a platform for securing software provisioning and extensions, stumbled upon. In a recent post Yomtov explains that while ...

Read full article

Affected Software

4 affected components
OpenVSX OpenVSX
Cursor Cursor
Windsurf Windsurf
Microsoft VS Code
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical zero-day vulnerability discovered in the infrastructure of AI coding tools, specifically affecting Cursor and Windsurf users.

2

What security implications are discussed in the article?

The vulnerability could allow a non-sophisticated attacker to hijack over 10 million users of the affected software, leading to potential data breaches.

3

What products or software are affected by the zero-day vulnerability?

The affected software includes Cursor, Windsurf, OpenVSX, and Microsoft VS Code.

4

Who discovered the zero-day vulnerability?

A security researcher from Koi Security discovered the critical zero-day vulnerability.

5

What could have been the impact of this zero-day if exploited?

If exploited, the zero-day could have compromised the security of over 10 million Cursor and Windsurf users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203