Cursor closes command execution gap before workspace trust
Cursor has patched a security flaw in its command-line coding agent that allowed a malicious repository to execute commands on a developer’s computer before the user was asked whether the workspace should be trusted. The weakness affected Cursor CLI’s worktree feature and could be triggered when a user launched the agent with the -w option inside a repository containing a specially crafted.…
We haven't written up this one. Arabian Post has the full story — the link below goes straight to it.