B
今週中
AIコードエディタ「Cursor」のWindows版において、ワークスペースのルートディレクトリに配置された偽の git.exe が優先的に実行される脆弱性
📌 一言でいうと
AIコードエディタ「Cursor」のWindows版において、ワークスペースのルートディレクトリに配置された偽の git.exe が優先的に実行される脆弱性が報告されました。攻撃者が悪意のあるファイルをリポジトリに含めて配布し、開発者がそのフォルダをCursorで開くと、警告なしに任意のコードが実行される恐れがあります。研究者が報告してから7ヶ月が経過していますが、現時点で修正パッチは提供されていません。
🔍該当判定
- Windows OSのPCで、AIコードエディタの『Cursor』をインストールして利用している
- Cursorを利用して、外部からダウンロードしたソースコードやGitHub上のリポジトリをWindows上で開いている
- 社内の開発者が、Windows環境でCursorを用いてプログラム開発を行っている
上記いずれにも該当しない → 静観でOK
✅該当時の対応
修正パッチが提供されるまで、信頼できないソースからのリポジトリをCursorで開かないこと。また、ワークスペースルートに不審な実行ファイル(git.exe等)が存在しないか確認することを推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Cursor AIエディタにおける任意コード実行の脆弱性について
お疲れさまです。Cursor AIエディタのWindows版における深刻な脆弱性に関する情報共有です。
■ 概要
CursorがGitバイナリを解決する際、ワークスペースのルートディレクトリにある git.exe を優先的に実行する仕様に起因する脆弱性です。攻撃者がリポジトリのルートに悪意のある git.exe を配置していた場合、ユーザーがそのフォルダを開くだけで、警告なしに任意のコードが実行されます。
■ 影響範囲
- 対象製品: Cursor (Windows版)
- バージョン: 現行の未修正バージョン
■ 対応手順
1. 開発チームに対し、信頼できない外部リポジトリをCursorで開くことのリスクを周知してください。
2. ワークスペースルートに不審な実行ファイルが配置されていないか、エンドポイント監視(EDR等)での検知ルール検討を推奨します。
3. ベンダーからの修正アップデートが公開され次第、速やかに適用してください。
■ 参考情報
- Mindgard 技術レポート (2026年7月14日公開)
対応優先度: 高
対応期限: 修正パッチ適用まで継続的な注意が必要
お疲れさまです。Cursor AIエディタのWindows版における深刻な脆弱性に関する情報共有です。
■ 概要
CursorがGitバイナリを解決する際、ワークスペースのルートディレクトリにある git.exe を優先的に実行する仕様に起因する脆弱性です。攻撃者がリポジトリのルートに悪意のある git.exe を配置していた場合、ユーザーがそのフォルダを開くだけで、警告なしに任意のコードが実行されます。
■ 影響範囲
- 対象製品: Cursor (Windows版)
- バージョン: 現行の未修正バージョン
■ 対応手順
1. 開発チームに対し、信頼できない外部リポジトリをCursorで開くことのリスクを周知してください。
2. ワークスペースルートに不審な実行ファイルが配置されていないか、エンドポイント監視(EDR等)での検知ルール検討を推奨します。
3. ベンダーからの修正アップデートが公開され次第、速やかに適用してください。
■ 参考情報
- Mindgard 技術レポート (2026年7月14日公開)
対応優先度: 高
対応期限: 修正パッチ適用まで継続的な注意が必要
Subject: [Security Advisory] Arbitrary Code Execution Vulnerability in Cursor AI Editor
Dear IT/Security Team,
We are sharing information regarding a critical vulnerability affecting the Windows version of the Cursor AI code editor.
■ Overview
Due to the way Cursor resolves the Git binary on Windows, it prioritizes a git.exe file located in the root of the workspace. An attacker can place a malicious binary named git.exe in a repository; when a developer opens that folder in Cursor, the binary is executed automatically without any user prompt or warning.
■ Scope
- Product: Cursor (Windows version)
- Version: Current unpatched versions
■ Recommended Actions
1. Alert development teams to avoid opening untrusted third-party repositories using Cursor.
2. Consider implementing EDR detection rules to monitor for suspicious git.exe processes launched by Cursor.exe.
3. Ensure the editor is updated immediately once a vendor patch is released.
■ Reference
- Mindgard Technical Report (Published July 14, 2026)
Priority: High
Deadline: Until a formal patch is applied
Dear IT/Security Team,
We are sharing information regarding a critical vulnerability affecting the Windows version of the Cursor AI code editor.
■ Overview
Due to the way Cursor resolves the Git binary on Windows, it prioritizes a git.exe file located in the root of the workspace. An attacker can place a malicious binary named git.exe in a repository; when a developer opens that folder in Cursor, the binary is executed automatically without any user prompt or warning.
■ Scope
- Product: Cursor (Windows version)
- Version: Current unpatched versions
■ Recommended Actions
1. Alert development teams to avoid opening untrusted third-party repositories using Cursor.
2. Consider implementing EDR detection rules to monitor for suspicious git.exe processes launched by Cursor.exe.
3. Ensure the editor is updated immediately once a vendor patch is released.
■ Reference
- Mindgard Technical Report (Published July 14, 2026)
Priority: High
Deadline: Until a formal patch is applied