SMRTR ProgrammingSep 10, 2025Daily.dev

Cursor’s autorun lets hackers execute arbitrary code

SMRTR summary

Cursor's AI-powered code editor contains a critical security flaw allowing hackers to execute malicious code automatically when developers open folders. The vulnerability exists because Workspace Trust is disabled by default, letting attackers craft repositories with hidden autorun tasks that can steal API keys, cloud credentials, and sensitive data without any user prompt or warning. This issue represents another case where user convenience trumped security, potentially enabling organization-wide compromises through a simple "open folder" action.

SMRTR provides this summary for quick context. The original article belongs to Daily.dev.

Read the original article
SMRTR Programming

Get the next batch of curated summaries in your inbox.

This archive is built from SMRTR newsletter summaries. Subscribe for hand-picked stories without the extra noise.