Musk's AI-driven programming assistant and code editor, Cursor, has been found to harbor a significant security vulnerability. This flaw allows attackers to plant a malicious git.exe file at the root level of a repository. Cursor, in turn, may execute this file preferentially or even directly, without any user prompt or warning. On December 15, 2025, the security firm Mindgard reported this vulnerability. However, as of April 2026, the issue remained replicable in Cursor version 3.2.16 for Windows. Despite Mindgard's repeated attempts to contact the developers during this period and receive no response, they ultimately decided to publicly disclose the vulnerability details on July 14, 2026.
