CVE-2026-63093 HIGH

CVE-2026-63093: Cursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace

Vendor Anysphere, Inc.
Product Cursor
Weakness CWE-426
Published July 17, 2026
Last update July 28, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and opens a crafted repository, Cursor automatically resolves and executes the workspace-resident git.exe during IDE startup and on a recurring timed cadence without any user interaction, running the malicious binary under the privileges of the current user.

Key dates

02Disclosure timeline

July 17, 2026 CVE published
July 28, 2026 Record updated