Information security
fromThe Hacker News
3 weeks agoCursor AI Code Editor Flaw Enables Silent Code Execution via Malicious Repositories
Cursor's default-disabled Workspace Trust allows VS Code-style autorun tasks to execute on folder open, enabling arbitrary code execution and potential credential theft.