Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Marc Lore says that AI will soon enable anyone open a restaurant

    May 6, 2026

    Altara secures $7M to bridge the data gap that’s slowing down physical sciences

    May 6, 2026

    India’s first GenAI unicorn shifts to cloud services as AI model ambitions face reality

    May 5, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Marc Lore says that AI will soon enable anyone open a restaurant
    • Altara secures $7M to bridge the data gap that’s slowing down physical sciences
    • India’s first GenAI unicorn shifts to cloud services as AI model ambitions face reality
    • OpenAI’s cozy partner Cerebras is on track for a blockbuster IPO
    • Katie Haun raises $1B for new venture funds
    • 5 days to get 50% off a second Disrupt 2026 pass
    • ‘This is fine’ creator says AI startup stole his art
    • Beyond Lovable and Mistral: 21 European startups to watch
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Security»This ‘critical’ Cursor security flaw could expose your code to malware – how to fix it
    Security

    This ‘critical’ Cursor security flaw could expose your code to malware – how to fix it

    TechurzBy TechurzSeptember 13, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    This 'critical' Cursor security flaw could expose your code to malware - how to fix it
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Shalitha Ranathunge/iStock/Getty Images Plus via Getty Images

    Follow ZDNET: Add us as a preferred source on Google.

    ZDNET’s key takeaways

    • A report found hackers can exploit an autorun feature in Cursor.
    • The danger is “significant,” but there’s an easy fix.
    • Cursor uses AI to assist with code-editing.

    A new report has uncovered what it describes as “a critical security vulnerability” in Cursor, the popular AI-powered code-editing platform.

    The report, published Wednesday by software company Oasis Security, found that code repositories within Cursor that contain the .vscode/tasks.json configuration can be instructed to automatically run certain functions as soon as the repositories are opened. Hackers could exploit that autorun feature via malware embedded into the code.

    Also: I did 24 days of coding in 12 hours with a $20 AI tool – but there’s one big pitfall

    “This has the potential to leak sensitive credentials, modify files, or serve as a vector for broader system compromise, placing Cursor users at significant risk from supply chain attacks,” Oasis wrote. 

    While Cursor and other AI-powered coding tools like Claude Code and Windsurf have become popular among software developers, the technology is still fraught with bugs. Replit, another AI coding assistant that debuted its newest agent earlier this week, recently deleted a company’s entire database.

    The security flaw

    According to Oasis’ report, the problem is rooted in the fact that Cursor’s “Workplace Trust” feature is disabled by default. 

    Basically, this feature is intended to be a verification step for Cursor users so that they only run code that they know and trust. Without it, the platform will automatically run code that’s in a repository, leaving the window open for bad actors to surreptitiously slip in malware that could then jeopardize a user’s system — and from there, potentially spread throughout a broader network.

    Also: I asked AI to modify mission-critical code, and what happened next haunts me

    Running code without the Workplace Trust feature could open “a direct path to unauthorized access with an organization-wide blast radius,” Oasis said. 

    In a statement to Oasis that was published in the report, Cursor said that its platform operates with Workplace Trust deactivated by default since it interferes with some of the core automated features that users routinely depend on. 

    “We recommend either enabling Workspace Trust or using a basic text editor when working with suspected malicious repositories,” the company said.

    Also: That new Claude feature ‘may put your data at risk,’ Anthropic admits

    Cursor also told Oasis that it would soon publish updated security guidelines regarding the Workspace Trust feature. 

    How to stay protected

    The solution, then, is to simply enable the Workplace Trust feature in Cursor. To do this, add the following security prompt to settings, and then restart the program:

    {

    “security.workspace.trust.enabled”: true, 

    “security.workspace.trust.StartupPrompt”: “always”

    ZDNET has reached out to Cursor for further comment. 

    code Critical Cursor expose fix flaw malware Security
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleYour Powerbeats Pro 2 are getting a serious upgrade – but there’s a catch
    Next Article How we feel about AI friends, OpenAI’s money, and vibe coding
    Techurz
    • Website

    Related Posts

    Opinion

    Another customer of troubled startup Delve suffered a big security incident

    April 23, 2026
    Opinion

    Sources: Cursor in talks to raise $2B+ at $50B valuation as enterprise growth surges

    April 17, 2026
    Opinion

    Anthropic says Claude Code subscribers will need to pay extra for OpenClaw usage

    April 4, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Our Picks

    Marc Lore says that AI will soon enable anyone open a restaurant

    May 6, 2026

    Altara secures $7M to bridge the data gap that’s slowing down physical sciences

    May 6, 2026

    India’s first GenAI unicorn shifts to cloud services as AI model ambitions face reality

    May 5, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.