www.infosecurity-magazine.com 8/11/2026, 2:47:35 PM · external

Cursor CLI flaw lets cloned repos run commands on dev machines

Cursor CLI flaw lets cloned repos run commands on dev machines
CyberSIXT Evidence Panel
Primary Source manifold.security

A security flaw in Cursor's command-line tool has been identified, which allows cloned repositories to run commands on a developer's machine without prior trust verification. Reported by Manifold Security, the issue concerns Cursor's worktree feature that inadvertently runs commands from a configuration file without sufficient safeguards. Despite a swift fix implemented three days post-report, Cursor classified the issue as 'informative,' denying it had security implications. Developers are advised to update to the latest build to mitigate risks.

View Primary Source Via www.infosecurity-magazine.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline