Drooid Logo
Back to today’s briefing

Story perspectives

Major Vulnerability in Cursor AI Editor Risks Developer Security

9/12/2025

44 10

1 of 1

Story summary
  • A vulnerability in the Cursor AI Code Editor permits remote code execution upon opening a project folder.
  • This issue stems from the default setting that disables the "Workspace Trust" feature, allowing automatic task execution without user consent.
  • Malicious repositories can exploit this flaw, embedding harmful instructions in project files.
  • Experts warn this could jeopardize sensitive developer credentials and enable supply chain attacks.
  • Users should enable Workspace Trust and handle untrusted repositories in isolated environments.