Researchers reported the flaw to Cursor in December, but it still remains in the popular AI coding platform and can be used in poisoned repo attacks.

Simple age-old bugs give bad actors access to developers' secrets and source code-rich environments.

Cursor runs a repo-root git.exe when a Windows project opens, enabling code execution as the user. Seven months later, no patch or advisory exists.