Oasis Security has uncovered a security flaw in the widely used AI-powered code editor, Cursor, that allows malicious repositories to silently execute code the moment a developer opens them. According to a disclosure shared with CSO ahead of its publication on Wednesday, the issue stems from how Cursor allows certain project settings to automatically trigger execution of tasks as soon as a folder is opened, without first asking for user approval.
See also: Critical Chrome Vulnerability – Use After Free: Fix Immediately!

Security leaders, while not surprised, see the discovery as yet another example where ease of use trumped secure defaults.
Cursor, a leading 'vibe coding' platform, converts natural language prompts into functional code – offering speed and power, while raising new concerns for enterprise security. A successful exploit would allow attackers to gain access to sensitive data within development environments, including API keys, cloud credentials, and SaaS sessions.
The vulnerability exists because Cursor ships with Workspace Trust disabled by default, allowing tasks to be automatically executed without explicit user approval. This allows attackers to inject a crafted “.vscode/tasks.json” file into public repositories, which can be configured to automatically execute tasks the moment a folder is opened — without prompting, without warning. This execution path could allow a malicious repository to compromise a developer’s computer through something as simple as browsing a project.
See also: CodeRabbit: Vulnerability allowed access to 1 million repositories

Trey Ford, head of strategy and trust at Bugcrowd, compared the vulnerability to old vulnerabilities like 'autorun.inf' on removable media, where simply inserting the media could launch malware.
Oasis researchers noted that the vulnerability does not affect Visual Studio Code. “Visual Studio Code enables Workspace Trust by default and restricts execution of dangerous hooks (tasks, debug preLaunchTask, and some extension triggers) until a folder is explicitly trusted,” they said. “The default for Cursor disables this protection, so automatic executions like runOn: 'folderOpen' are triggered without a consent prompt.”
The disclosure is not an isolated scenario. Earlier this year, Cursor was already targeted by campaigns like CurXecute and MCPoison, along with npm package spoofing targeting macOS users. Barr warned that the .vscode/tasks.json is “just another piece of the same puzzle: attackers are digging deep into the Cursor ecosystem to uncover any path to execution.”
See also: Vulnerabilities fixed in AI Cursor code editor

Hinting at an investment, “Cursor is at the point where it is being compared to (and increasingly targeted as) Microsoft’s Visual Studio. That’s a reason for a high-five and a nod to further strengthening and expanding enterprise security capabilities.” To mitigate the issue, Oasis researchers advise enabling Workspace Trust and taking extra care with unknown repositories – such as opening them elsewhere, reviewing them first, and limiting exposed secrets.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
