← Vulnerability feed

Vulnerability record · CVE-2026-63093 · published 17 July 2026

CVE-2026-63093: Anysphere cursor untrusted search path vulnerability

Anysphere · Cursor

Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and opens a crafted repository, Cursor automatically resolves and executes the workspace-resident git.exe during IDE startup and on a recurring timed cadence without any user interaction, running the malicious binary under the privileges of the current user.

8.7 CVSS 4.0 High EPSS 0.85% · top 43.6% CWE-426 · Untrusted search path
8.7CVSS 4.0 base score
0.85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
14 Aug 2026Last modified by NVD

Description

Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and opens a crafted repository, Cursor automatically resolves and executes the workspace-resident git.exe during IDE startup and on a recurring timed cadence without any user interaction, running the malicious binary under the privileges of the current user.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-63093 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-26268Anysphere cursor missing authorization vulnerabilityCursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicio…EPSS 0.42%9.8CVE-2025-59944Anysphere cursor vulnerabilityCursor is a code editor built for programming with AI. Versions 1.6.23 and below contain case-sensitive checks in the way Cursor IDE protects its sen…EPSS 0.41%9.8CVE-2025-54130Anysphere cursor improper authorization vulnerabilityCursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions less than 1.3.9. If…EPSS 0.30%9.8CVE-2025-54135Anysphere cursor os command injection vulnerabilityCursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions below 1.3.9, If the…EPSS 1.8%9.3CVE-2026-50548Anysphere cursor path traversal vulnerabilityCursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox gra…EPSS 1.0%9.3CVE-2026-50549Anysphere cursor link following vulnerabilityCursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, the…EPSS 1.0%8.8CVE-2025-64106Anysphere cursor os command injection vulnerabilityCursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor's MCP server installation ena…EPSS 0.37%8.8CVE-2025-64107Anysphere cursor path traversal vulnerabilityCursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may lead to RCE. Cursor detects p…EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2026-63093), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.