完全披露:Cursor 中的任意代码执行漏洞
来源:mindgard.ai — 2026-07-16
📋 概述
安全研究者公开了 Cursor 编辑器中的任意代码执行漏洞详情,探讨了负责任的漏洞披露策略和时间线。
🔑 核心要点
- Cursor 0day: When Full Disclosure Becomes the Only Protection Left - Mindgard Platform Platform Research Led.
- Enterprise Ready AI Discovery & Recon Discover shadow AI and agents.
- By creating a repository with a planted malicious git.exe in the root, the IDE will execute it with no user interaction and no prompting of the user.
- This occurs repeatedly on a cadence.
- Sometimes security research uncovers deeply technical vulnerabilities that require pages of explanation.
💡 金句
Cursor 0day: When Full Disclosure Becomes the Only Protection Left - Mindgard Platform Platform Research Led.
← 返回 Lobsters 首页