SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-63093

HIGH · CVSS 8.8 EPSS 0.56% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Cursor for Windows version 3.2.16 is vulnerable to a binary planting flaw that enables remote attackers to execute arbitrary code by placing a malicious git.exe file in the repository root. This vulnerability allows the malicious binary to run automatically during IDE startup and periodically without user interaction, executing with the current user's privileges. Developers and organizations using this version of Cursor should prioritize patching to mitigate the risk of unauthorized code execution.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-63093
Severity
HIGH
CVSS
8.8
EPSS
0.56%
Windows

Original NVD Description

Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and opens a crafted repository, Cursor automatically resolves and executes the workspace-resident git.exe during IDE startup and on a recurring timed cadence without any user interaction, running the malicious binary under the privileges of the current user.

Related CVEs

Other vulnerabilities affecting the same vendor(s)