Cursor IDE Zero-Day Vulnerability Disclosed After Six Months Without Patch (heise.de)
0xBASE INTEL BRIEF
- Critical flaw in Cursor IDE enables code execution via malicious file.
- Portnoy reported bug in Dec 2025; vendor did not patch.
- After six months, Portnoy disclosed vulnerability publicly.
- Jürgen Schmidt claims coordinated disclosure is obsolete.
"Security researcher Aaron Portnoy has publicly disclosed a critical vulnerability in the AI-powered Cursor IDE after the vendor failed to issue a fix for over six months. The flaw allows arbitrary code execution via a malicious 'git.exe' file. Portnoy, founder of the pwn2own contest, resorted to full disclosure, reigniting debate over coordinated disclosure's viability."
no comments yet.