Colleagues, please note: on Windows, a cloned repository in Cursor can trigger a malicious git.exe

Colleagues, I’d like to draw your attention to a cybersecurity issue.
A vulnerability in Cursor on Windows appears to allow the editor to execute a git.exe file placed in a project root when opening a repository.
No click, no warning, and no additional prompt. This could give an attacker code execution under the current user account.
Source code, SSH keys, and cloud tokens may be at risk.
There is no patch yet, so I would treat untrusted repositories as executable content.
Why this matters: it is safer to open such projects in Windows Sandbox or an isolated VM, and to strengthen AppLocker/WDAC on managed devices.
How do you review repositories?
#cybersecurity #WindowsSecurity #Vulnerability #AppSec

