Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
← All Cursor issues

This week in Cursor · Jul 20, 2026

Cursor AI July 20: Unpatched Windows 0-Day Auto-Runs Malicious git.exe From Cloned Repos, Cursor in Slack Adds Plan-First Responses and Multi-Repo Environments

Get the next issue in your inbox. Weekly · Free

unsubscribe anytime.

TLDR;

The week's biggest Cursor story is a security one. On July 15, Mindgard fully disclosed an unpatched Windows flaw: Cursor automatically executes a git.exe binary found at a cloned project's root when the folder is opened - no clicks, no prompts - running attacker code as the logged-in user with access to SSH keys and cloud credentials. Reported December 15, 2025, initially closed as out of scope, and still unpatched in Cursor 3.11 with no CVE or advisory. On the product side, Cursor in Slack (July 17) now shares a plan before starting, runs in named multi-repo environments, and works across channels and threads, and Cursor doubled included usage for Grok 4.5 and Composer 2.5 on all paid tiers on July 16. Until a patch ships, inspect cloned repos for root-level executables before opening them in Cursor on Windows.

Cursor IDE & App

Cursor AI 0-day on Windows: malicious git.exe in a cloned repo auto-executes with no user interaction - no patch, Cursor 3.11 still vulnerable

  • On July 15, AI security firm Mindgard published full details of an unpatched flaw: on Windows, Cursor automatically executes a git.exe binary found at a project's root when the folder is opened, with no clicks, prompts or approval dialogs, giving the attacker code execution as the logged-in user with access to SSH keys and cloud credentials.
  • Mindgard reported it December 15, 2025; Cursor's HackerOne program first closed it as out of scope, and current release 3.11 is reportedly still vulnerable with no CVE, no advisory and no patch.

Editor’s read: Treat every clone-and-open on Windows as untrusted code execution until Cursor ships a fix - check repo roots for executables first.

Cursor in Slack update: plan-first responses, multi-repo environments, cross-channel workflows

  • On July 17, Cursor's changelog detailed a Slack upgrade: Cursor now responds with a plan before it begins so you can redirect early, starts in named multi-repo environments (with a Switch repository prompt when it needs a repo outside the current one), and can read from and post to other Slack channels and threads during a task.

Editor’s read: If your frontend, backend and shared code live in separate repos, the named multi-repo environments finally make Slack-triggered tasks practical.

Community & Independent Developers

Competitor Dev Tools

Action Items

Immediate

  • On Windows, inspect every cloned repo for executables (especially git.exe) at the project root before opening it in Cursor - the auto-execution flaw is unpatched as of Cursor 3.11
  • If your team triggers Cursor from Slack across multiple repos, set up named multi-repo environments to stop single-repo mistargeting
  • Use the doubled Grok 4.5 and Composer 2.5 included usage - it applies to all paid tiers as of July 16

All Resources

Every Monday morning

This week in Cursor

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.