Story perspectives
Major Vulnerability in Cursor AI Editor Risks Developer Security
9/12/2025
44 10
1 of 1
Story summary
- A vulnerability in the Cursor AI Code Editor permits remote code execution upon opening a project folder.
- This issue stems from the default setting that disables the "Workspace Trust" feature, allowing automatic task execution without user consent.
- Malicious repositories can exploit this flaw, embedding harmful instructions in project files.
- Experts warn this could jeopardize sensitive developer credentials and enable supply chain attacks.
- Users should enable Workspace Trust and handle untrusted repositories in isolated environments.
