Saturday, September 13, 2025
No Result
View All Result
DOLLAR BITCOIN
Shop
  • Home
  • Blockchain
  • Bitcoin
  • Cryptocurrency
  • Altcoin
  • Ethereum
  • DeFi
  • Legal Hub
  • More
    • Market & Analysis
    • Dogecoin
    • NFTs
    • XRP
    • Regulations
  • Shop
    • Bitcoin Book
    • Bitcoin Coin
    • Bitcoin Hat
    • Bitcoin Merch
    • Bitcoin Miner
    • Bitcoin Miner Machine
    • Bitcoin Shirt
    • Bitcoin Standard
    • Bitcoin Wallet
DOLLAR BITCOIN
No Result
View All Result
Home Blockchain

This ‘critical’ Cursor security flaw could expose your code to malware – how to fix it

n70products by n70products
September 13, 2025
in Blockchain
0
This ‘critical’ Cursor security flaw could expose your code to malware – how to fix it
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter


gettyimages-2197446069

Shalitha Ranathunge/iStock/Getty Pictures Plus by way of Getty Pictures

Comply with ZDNET: Add us as a preferred source on Google.


ZDNET’s key takeaways

  • A report discovered hackers can exploit an autorun characteristic in Cursor.
  • The hazard is “vital,” however there’s a simple repair.
  • Cursor makes use of AI to help with code-editing.

A brand new report has uncovered what it describes as “a vital safety vulnerability” in Cursor, the favored AI-powered code-editing platform.

The report, revealed Wednesday by software program firm Oasis Safety, discovered that code repositories inside Cursor that comprise the .vscode/duties.json configuration might be instructed to routinely run sure features as quickly because the repositories are opened. Hackers might exploit that autorun characteristic by way of malware embedded into the code.

Additionally: I did 24 days of coding in 12 hours with a $20 AI tool – but there’s one big pitfall

“This has the potential to leak delicate credentials, modify recordsdata, or function a vector for broader system compromise, putting Cursor customers at vital threat from provide chain assaults,” Oasis wrote. 

Whereas Cursor and different AI-powered coding instruments like Claude Code and Windsurf have turn into fashionable amongst software program builders, the know-how remains to be fraught with bugs. Replit, one other AI coding assistant that debuted its newest agent earlier this week, lately deleted a company’s entire database.

The safety flaw

In line with Oasis’ report, the issue is rooted in the truth that Cursor’s “Office Belief” characteristic is disabled by default. 

Mainly, this characteristic is meant to be a verification step for Cursor customers in order that they solely run code that they know and belief. With out it, the platform will routinely run code that is in a repository, leaving the window open for dangerous actors to surreptitiously slip in malware that might then jeopardize a consumer’s system — and from there, doubtlessly unfold all through a broader community.

Additionally: I asked AI to modify mission-critical code, and what happened next haunts me

Operating code with out the Office Belief characteristic might open “a direct path to unauthorized entry with an organization-wide blast radius,” Oasis mentioned. 

In an announcement to Oasis that was revealed within the report, Cursor mentioned that its platform operates with Office Belief deactivated by default because it interferes with a few of the core automated options that customers routinely rely on. 

“We suggest both enabling Workspace Belief or utilizing a fundamental textual content editor when working with suspected malicious repositories,” the corporate mentioned.

Additionally: That new Claude feature ‘may put your data at risk,’ Anthropic admits

Cursor additionally advised Oasis that it might quickly publish up to date safety tips relating to the Workspace Belief characteristic. 

Methods to keep protected

The answer, then, is to easily allow the Office Belief characteristic in Cursor. To do that, add the next safety immediate to settings, after which restart this system:

{

“safety.workspace.belief.enabled”: true, 

“safety.workspace.belief.StartupPrompt”: “all the time”

ZDNET has reached out to Cursor for additional remark. 





Source link

Tags: CodeCriticalCursorExposefixFlawmalwareSecurity
Previous Post

Bitcoin and Ethereum ETFs See Inflows Amid Rising Institutional Confidence

Next Post

Ethereum – Can ETH target $5,000 as KEY metric hits record high?

Next Post
Ethereum – Can ETH target $5,000 as KEY metric hits record high?

Ethereum - Can ETH target $5,000 as KEY metric hits record high?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Premium Content

Ethereum Price Struggles to Sustain Gains: Is the Uptrend in Trouble?

Ethereum Price Struggles to Sustain Gains: Is the Uptrend in Trouble?

August 15, 2024
Texas Bitcoin Reserve Bill clears key legislative hurdle, awaits final vote

Texas Bitcoin Reserve Bill clears key legislative hurdle, awaits final vote

May 21, 2025
Did Ethereum Survive The Storm? Analyst Eyes Breakout Next

Did Ethereum Survive The Storm? Analyst Eyes Breakout Next

April 16, 2025
The potential to empower disenfranchised communities in Latin America using Ethereum

The potential to empower disenfranchised communities in Latin America using Ethereum

January 29, 2024
I spent a week in New York City with the Samsung Z Fold 7 – and it spoiled me big time

I spent a week in New York City with the Samsung Z Fold 7 – and it spoiled me big time

July 25, 2025
eth2 quick update no. 21

eth2 quick update no. 21

September 14, 2024

Recent Posts

  • Japan Plans Major Crypto Tax Cut — From 55% Down to 20% in 2025
  • I built my own AirTag-like tracker with this Raspberry Pi alternative – how it works
  • XRP Price At $23, Dogecoin To $2, And Solana At $1,800? Analyst Unveils 2026 Predictions

Categories

  • Altcoin
  • Bitcoin
  • Blockchain
  • Blog
  • Cryptocurrency
  • DeFi
  • Dogecoin
  • Ethereum
  • Market & Analysis
  • NFTs
  • Regulations
  • XRP

Recommended

Japan Plans Major Crypto Tax Cut — From 55% Down to 20% in 2025

Japan Plans Major Crypto Tax Cut — From 55% Down to 20% in 2025

September 13, 2025
I built my own AirTag-like tracker with this Raspberry Pi alternative – how it works

I built my own AirTag-like tracker with this Raspberry Pi alternative – how it works

September 13, 2025

© 2025 Dollar-Bitcoin | All Rights Reserved

No Result
View All Result
  • Home
  • Blockchain
  • Bitcoin
  • Cryptocurrency
  • Altcoin
  • Ethereum
  • DeFi
  • Legal Hub
  • More
    • Market & Analysis
    • Dogecoin
    • NFTs
    • XRP
    • Regulations
  • Shop
    • Bitcoin Book
    • Bitcoin Coin
    • Bitcoin Hat
    • Bitcoin Merch
    • Bitcoin Miner
    • Bitcoin Miner Machine
    • Bitcoin Shirt
    • Bitcoin Standard
    • Bitcoin Wallet

© 2025 Dollar-Bitcoin | All Rights Reserved

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
💵 Turn Every Dollar Into Crypto Rewards! Wirex lets you spend dollars or bitcoin — and get up to 8% back in crypto instantly. 💸 Exclusive offers dropping soon — stay tuned!
“Offers Launching Soon”
This is default text for notification bar
Learn more
Go to mobile version