<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/cursor-0day-when-full-disclosure-becomes-the-only-protection-left-dxmpfvbvn" -->

---
title: Cursor 0day: When Full Disclosure Becomes the Only...
description: Mindgard discloses a zero-day vulnerability in Cursor IDE affecting Windows users: when a repository contains a malicious git.exe in its root directory, Cursor...
canonical: https://daily.dev/posts/cursor-0day-when-full-disclosure-becomes-the-only-protection-left-dxmpfvbvn
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Cursor 0day: When Full Disclosure Becomes the Only Protection Left | daily.dev
og:description: Mindgard discloses a zero-day vulnerability in Cursor IDE affecting Windows users: when a repository contains a malicious git.exe in its root directory, Cursor...
og:url: https://daily.dev/posts/cursor-0day-when-full-disclosure-becomes-the-only-protection-left-dxmpfvbvn
og:image: https://api.daily.dev/og/posts/DXMPFVBvN.png
og:image:alt: Cursor 0day: When Full Disclosure Becomes the Only Protection Left
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Cursor 0day: When Full Disclosure Becomes the Only Protection Left

**[Hacker News](https://daily.dev/sources/hn)** · 8 min read · 0 upvotes · 0 comments

## Summary

Mindgard discloses a zero-day vulnerability in Cursor IDE affecting Windows users: when a repository contains a malicious git.exe in its root directory, Cursor automatically executes it with no user interaction, resulting in arbitrary code execution. The bug was first reported on December 15, 2025, and despite seven months of follow-ups through official channels, HackerOne, and direct outreach to Cursor leadership, the vulnerability remains unpatched across 197+ versions. Mindgard is resorting to full public disclosure after all coordinated disclosure attempts failed. Mitigations include using AppLocker/Windows App Control policies on managed systems, or opening untrusted repositories only in isolated VMs. The post also raises broader concerns about security accountability in rapidly growing AI coding tool companies.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left>

## Similar posts on daily.dev

- [Cursor’s Unpatched Zero-Day Lets a Fake git.exe Hijack Any Windows Developer](https://daily.dev/posts/cursor-s-unpatched-zero-day-lets-a-fake-git-exe-hijack-any-windows-developer-risodnpvx) · Latest Hacking News · 9 upvotes · 4 comments
- [Critical Cursor bug could turn routine Git into RCE](https://daily.dev/posts/critical-cursor-bug-could-turn-routine-git-into-rce-pedjrotwl) · CSO Online · 0 upvotes · 1 comments

---

Tags: [#security](https://daily.dev/tags/security)

[View this post on daily.dev](https://daily.dev/posts/cursor-0day-when-full-disclosure-becomes-the-only-protection-left-dxmpfvbvn)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Cursor 0day: When Full Disclosure Becomes the Only Protection Left","url":"https://daily.dev/posts/cursor-0day-when-full-disclosure-becomes-the-only-protection-left-dxmpfvbvn","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/cursor-0day-when-full-disclosure-becomes-the-only-protection-left-dxmpfvbvn"},"datePublished":"2026-07-14T20:26:27.644Z","dateModified":"2026-07-15T10:59:09.246Z","description":"Mindgard discloses a zero-day vulnerability in Cursor IDE affecting Windows users: when a repository contains a malicious git.exe in its root directory, Cursor...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1fa0f504b00571631d18dd5d941b0464?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1fa0f504b00571631d18dd5d941b0464?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Hacker News","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Hacker News","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/hn","url":"https://daily.dev/sources/hn"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/cursor-0day-when-full-disclosure-becomes-the-only-protection-left-dxmpfvbvn","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security","timeRequired":"PT8M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Hacker News","item":"https://daily.dev/sources/hn"},{"@type":"ListItem","position":3,"name":"Cursor 0day: When Full Disclosure Becomes the Only Protection Left"}]}
```

