Cursor flaw allows repo-root binaries to run
🛡️ Open a repository in Cursor on Windows and, if a file named git.exe is in the project root, Cursor runs it automatically without prompt. Whatever that binary does executes as the logged-in user and Cursor repeatedly spawns it while the project remains open. Mindgard reported the issue in December 2025, published full details seven months later, and no patch or Cursor advisory had been issued as of July 15, 2026.
