Information security
fromThe Hacker News
21 hours agoCursor AI Code Editor Flaw Enables Silent Code Execution via Malicious Repositories
Cursor's default-disabled Workspace Trust allows VS Code-style autorun tasks to execute on folder open, enabling arbitrary code execution and potential credential theft.