Cursor, VS Code, and Antigravity are the best AI editors most of us have ever used. Here's the new 1-click RCE bug, and what to do about it today.

The three editors developers are leaning on hardest right now — Cursor, Microsoft Visual Studio Code, and Google Antigravity — just got hit with a disclosure worth taking seriously: a one-click remote code execution flaw where the trigger is a link inside a commit message. Click the link, and your endpoint belongs to whoever embedded the command.

This is the kind of bug that reads as theoretical until it isn't. Most teams using these tools are flying through AI-assisted edits, trusting the editor to be on their side. It isn't always.

What the disclosure actually says

Per the IT Security News write-up of the 2026-08-05 disclosure, the flaw lets an attacker hide malicious commands inside links placed in commit messages. The victim clicks the link — a routine action — and arbitrary code runs on the developer's machine. The "1-click" in the name isn't marketing; it's the whole attack. One click, full endpoint compromise.