Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace
Vulnerability Description
Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and opens a crafted repository, Cursor automatically resolves and executes the workspace-resident git.exe during IDE startup and on a recurring timed cadence without any user interaction, running the malicious binary under the privileges of the current user.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
不可信的搜索路径
Vulnerability Title
Anysphere Cursor 权限许可和访问控制问题漏洞
Vulnerability Description
anysphere cursor是美国anysphere公司的一款AI代码编辑器。 Anysphere Cursor 3.2.16版本存在权限许可和访问控制问题漏洞,该漏洞源于存在二进制种植漏洞,通过在仓库根目录放置恶意git.exe文件,当开发者克隆并打开精心构造的仓库时,Cursor在IDE启动时自动解析并执行工作区中的git.exe,无需用户交互即可在当前用户权限下运行恶意二进制文件,可能导致远程攻击者实现任意代码执行。
CVSS Information
N/A
Vulnerability Type
N/A