A vulnerability in the Cursor development environment allows for arbitrary code execution when a malicious git.exe is present in the repository root. The issue was first reported to Cursor in December 2025, but remains unfixed despite multiple follow-ups. The vulnerability can be exploited by opening a project containing a malicious git.exe, with no user interaction or prompts required. This has raised concerns about the security practices of Cursor, a widely-used AI-assisted development environment.