• News/
  • https://www.zdnet.com/article/this-critical-cursor-security-flaw-could-expose-your-code-to-malware-how-to-fix-it/

This 'critical' Cursor security flaw could expose your code to malware - how to fix it

ZDNet
·
Webb Wright
·
Published Sep 12, 2025
·
Updated

Follow ZDNET: Add us as a preferred source on Google. A new report has uncovered what it describes as "a critical security vulnerability" in Cursor, the popular AI-powered code-editing platform. The report, published Wednesday by software company Oasis Security, found that code repositories within Cursor that contain the .vscode/tasks.json configuration can be instructed to automatically run certain functions as soon as the repositories are opened. Hackers could exploit that autorun feature via malware embedded into the code. Also: I did 24 days of coding in 12 hours with a $20 AI tool - but there's one big pitfall "This has the potential to leak sensitive credentials, modify files, or serve as a vector for broader system compromise, placing Cursor users at significant risk from supply chain attacks," Oasis wrote. While Cursor and other AI-powered coding tools like Claude Code and Windsurf have become popular among software developers, the technology is still fraught with bugs. Replit, another AI coding assistant that debuted its newest agent earlier this week, recently deleted a company's entire database. According to Oasis' report, the problem is rooted in the fact that Cursor's "Workplace Trust" feature is disabled by default. Basically, this feature is intended to be a verification step for Cursor users so that they only run code that they know and trust. Without it, the platform will automatically run code that's in a repository, leaving the window open for bad actors to...

Read full article

Affected Software

1 affected component
Cursor Cursor
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical security vulnerability found in the Cursor AI-powered code-editing platform.

2

What security implications are discussed in the article?

The vulnerability could expose users' code to malware, posing significant risks to their projects and sensitive information.

3

What software is affected by the security flaw?

The affected software is Cursor, the AI-powered code-editing platform.

4

What should users do in response to this vulnerability?

Users are advised to follow specific instructions provided in the article to effectively mitigate the security risks.

5

How was the vulnerability discovered?

The vulnerability was uncovered in a security report detailing potential exposure to malware through the Cursor platform.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203