This week in Cursor · Jul 20, 2026
Cursor AI July 20: Unpatched Windows 0-Day Auto-Runs Malicious git.exe From Cloned Repos, Cursor in Slack Adds Plan-First Responses and Multi-Repo Environments
Get the next issue in your inbox. Weekly · Free
The week's biggest Cursor story is a security one. On July 15, Mindgard fully disclosed an unpatched Windows flaw: Cursor automatically executes a git.exe binary found at a cloned project's root when the folder is opened - no clicks, no prompts - running attacker code as the logged-in user with access to SSH keys and cloud credentials. Reported December 15, 2025, initially closed as out of scope, and still unpatched in Cursor 3.11 with no CVE or advisory. On the product side, Cursor in Slack (July 17) now shares a plan before starting, runs in named multi-repo environments, and works across channels and threads, and Cursor doubled included usage for Grok 4.5 and Composer 2.5 on all paid tiers on July 16. Until a patch ships, inspect cloned repos for root-level executables before opening them in Cursor on Windows.
Cursor IDE & App
Cursor AI 0-day on Windows: malicious git.exe in a cloned repo auto-executes with no user interaction - no patch, Cursor 3.11 still vulnerable
- On July 15, AI security firm Mindgard published full details of an unpatched flaw: on Windows, Cursor automatically executes a git.exe binary found at a project's root when the folder is opened, with no clicks, prompts or approval dialogs, giving the attacker code execution as the logged-in user with access to SSH keys and cloud credentials.
- Mindgard reported it December 15, 2025; Cursor's HackerOne program first closed it as out of scope, and current release 3.11 is reportedly still vulnerable with no CVE, no advisory and no patch.
Editor’s read: Treat every clone-and-open on Windows as untrusted code execution until Cursor ships a fix - check repo roots for executables first.
Cursor in Slack update: plan-first responses, multi-repo environments, cross-channel workflows
- On July 17, Cursor's changelog detailed a Slack upgrade: Cursor now responds with a plan before it begins so you can redirect early, starts in named multi-repo environments (with a Switch repository prompt when it needs a repo outside the current one), and can read from and post to other Slack channels and threads during a task.
Editor’s read: If your frontend, backend and shared code live in separate repos, the named multi-repo environments finally make Slack-triggered tasks practical.
Community & Independent Developers
Cursor doubles included Grok 4.5 and Composer 2.5 usage as Claude Code, Codex and Cursor all reset limits on July 16
- On July 16, Cursor doubled the included usage allowance for Grok 4.5 and Composer 2.5 across all paid subscription tiers, the same day Anthropic and OpenAI refreshed their own quotas.
- a coordinated retention war among AI coding platforms.
Claude Code vs Codex vs Cursor vs Grok Build: the July 2026 state of play for AI coding agents
- On July 19, claude-world.com published a market snapshot arguing there is no universal winner.
- the right choice depends on matching the model-plus-harness combination to your workload, failure tolerance and scale, with practical evaluation requiring real tasks measured on patch correctness, verification discipline, recovery, isolation and total cost.
Competitor Dev Tools
Kimi K3: Moonshot AI's 2.8 trillion parameter open-source model tops a major coding benchmark
- On July 18, coverage of Moonshot AI's Kimi K3 highlighted the largest open-weight model yet - 2.8 trillion parameters with a one-million-token context window and a 76% win rate on the Frontend Code Arena - with open weights promised by July 27, 2026.
- Developers using Cursor are actively cross-shopping K3 as a coding model this week.
Gemini 3.5 Pro misses its third launch deadline as Google eyes a stopgap Gemini 3.6 Flash
- On July 15, reports confirmed Gemini 3.5 Pro missed its July 17 general-availability target.
- the third slip since June.
- leaving Claude, GPT-5.6 and Grok as the frontier model options Cursor users can pick from while Google regroups.
Action Items
Immediate
- On Windows, inspect every cloned repo for executables (especially git.exe) at the project root before opening it in Cursor - the auto-execution flaw is unpatched as of Cursor 3.11
- If your team triggers Cursor from Slack across multiple repos, set up named multi-repo environments to stop single-repo mistargeting
- Use the doubled Grok 4.5 and Composer 2.5 included usage - it applies to all paid tiers as of July 16
All Resources
This week in Cursor
Five minutes, every Monday - the tools, releases and tactics for developers.