Tuesday, November 4, 2025
SCRYPTO MAGAZINE
No Result
View All Result
  • Home
  • Crypto
  • Bitcoin
  • Blockchain
  • Market
  • Ethereum
  • Altcoins
  • XRP
  • Dogecoin
  • NFTs
  • Regualtions
SCRYPTO MAGAZINE
No Result
View All Result
Home NFTs

This ‘critical’ Cursor security flaw could expose your code to malware – how to fix it

SCRYPTO MAGAZINE by SCRYPTO MAGAZINE
September 12, 2025
in NFTs
0
This ‘critical’ Cursor security flaw could expose your code to malware – how to fix it
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Related articles

The top 10 products readers bought in October (no. 1 is under $20)

The top 10 products readers bought in October (no. 1 is under $20)

November 4, 2025
This 30-second routine keeps my Samsung Galaxy watch running like new every month

This 30-second routine keeps my Samsung Galaxy watch running like new every month

November 3, 2025


gettyimages-2197446069

Shalitha Ranathunge/iStock/Getty Photographs Plus through Getty Photographs

Comply with ZDNET: Add us as a preferred source on Google.


ZDNET’s key takeaways

  • A report discovered hackers can exploit an autorun function in Cursor.
  • The hazard is “important,” however there’s a simple repair.
  • Cursor makes use of AI to help with code-editing.

A brand new report has uncovered what it describes as “a essential safety vulnerability” in Cursor, the favored AI-powered code-editing platform.

The report, revealed Wednesday by software program firm Oasis Safety, discovered that code repositories inside Cursor that comprise the .vscode/duties.json configuration might be instructed to mechanically run sure features as quickly because the repositories are opened. Hackers might exploit that autorun function through malware embedded into the code.

Additionally: I did 24 days of coding in 12 hours with a $20 AI tool – but there’s one big pitfall

“This has the potential to leak delicate credentials, modify recordsdata, or function a vector for broader system compromise, inserting Cursor customers at important threat from provide chain assaults,” Oasis wrote. 

Whereas Cursor and different AI-powered coding instruments like Claude Code and Windsurf have grow to be widespread amongst software program builders, the expertise remains to be fraught with bugs. Replit, one other AI coding assistant that debuted its newest agent earlier this week, lately deleted a user’s entire database.

The safety flaw

In response to Oasis’ report, the issue is rooted in the truth that Cursor’s “Office Belief” function is disabled by default. 

Mainly, this function is meant to be a verification step for Cursor customers in order that they solely run code that they know and belief. With out it, the platform will mechanically run code that is in a repository, leaving the window open for dangerous actors to surreptitiously slip in malware that would then jeopardize a person’s system — and from there, probably unfold all through a broader community.

Additionally: I asked AI to modify mission-critical code, and what happened next haunts me

Working code with out the Office Belief function might open “a direct path to unauthorized entry with an organization-wide blast radius,” Oasis mentioned. 

In a press release to Oasis that was revealed within the report, Cursor mentioned that its platform operates with Office Belief deactivated by default because it interferes with a few of the core automated options that customers routinely rely on. 

“We advocate both enabling Workspace Belief or utilizing a fundamental textual content editor when working with suspected malicious repositories,” the corporate mentioned.

Additionally: That new Claude feature ‘may put your data at risk,’ Anthropic admits

Cursor additionally advised Oasis that it might quickly publish up to date safety pointers relating to the Workspace Belief function. 

Easy methods to keep protected

The answer, then, is to easily allow the Office Belief function in Cursor. To do that, add the next safety immediate to settings, after which restart this system:

{

“safety.workspace.belief.enabled”: true, 

“safety.workspace.belief.StartupPrompt”: “at all times”

ZDNET has reached out to Cursor for additional remark. 





Source link

Tags: CodeCriticalCursorExposefixflawmalwareSecurity
Share76Tweet47

Related Posts

The top 10 products readers bought in October (no. 1 is under $20)

The top 10 products readers bought in October (no. 1 is under $20)

by SCRYPTO MAGAZINE
November 4, 2025
0

The vacations are on the best way with Black Friday just some weeks away. Retailers like Amazon, Best Buy, and Walmart have been...

This 30-second routine keeps my Samsung Galaxy watch running like new every month

This 30-second routine keeps my Samsung Galaxy watch running like new every month

by SCRYPTO MAGAZINE
November 3, 2025
0

Kerry Wan/ZDNETComply with ZDNET: Add us as a preferred source on Google. ZDNET's key takeaways Clearing cache accelerates a sluggish...

I tucked a stealthy $15 tracker into my favorite jacket – now I no longer travel without it

I tucked a stealthy $15 tracker into my favorite jacket – now I no longer travel without it

by SCRYPTO MAGAZINE
November 3, 2025
0

Elevation Lab TagVault fabric mounting tag ZDNET's key takeaways Elevation Lab's TagVault is $14.99 on Amazon, and is available in...

Wearing the Meta Ray-Bans’ successor left me with two verdicts (and you’ll want to hear both)

Wearing the Meta Ray-Bans’ successor left me with two verdicts (and you’ll want to hear both)

by SCRYPTO MAGAZINE
November 2, 2025
0

ZDNET's key takeaways The most recent sensible glasses can be found for $379 in numerous types and lens choices. They...

Are laser-powered tape measures legit? It took just minutes to make me a believer

Are laser-powered tape measures legit? It took just minutes to make me a believer

by SCRYPTO MAGAZINE
November 2, 2025
0

Mileseey S50 laser measuring tool ZDNET's key takeaways The Mileseey S50 is obtainable now for $129.It is a pocket-sized laser...

Load More
  • Trending
  • Comments
  • Latest
Analysts’ 2025 Bull Market Predictions

Bitcoin Entering Second ‘Price Discovery Uptrend’, What’s Ahead?

January 21, 2025
Bitcoin Spot-Perpetual Price Gap Turns Negative

Bitcoin Spot-Perpetual Price Gap Turns Negative

December 23, 2024
Bitcoin Price Flashes Major Buy Signal On The 4-Hour TD Sequential Chart, Where To Enter?

Bitcoin Price Flashes Major Buy Signal On The 4-Hour TD Sequential Chart, Where To Enter?

December 24, 2024
Cardano Price Outlook: The $0.40 Threshold Could Unlock Doors to $1

Cardano Price Outlook: The $0.40 Threshold Could Unlock Doors to $1

December 23, 2024
Bitcoin could reach this unbelievable price by 2025, but these factors must align

Bitcoin could reach this unbelievable price by 2025, but these factors must align

0
XRP Consolidation Could End Once It Clears $2.60 – Top Analyst Expects $4 Soon

XRP Consolidation Could End Once It Clears $2.60 – Top Analyst Expects $4 Soon

0

Fed Can’t Hold Bitcoin, No Plans Yet To Change Law, Powell Says

0
Bears Take Full Control of the Market

Bears Take Full Control of the Market

0
Ethereum Treasury Has Seen Sharp Demand, But ETH’s Price Action Shows Weak Follow-Through

Ethereum Treasury Has Seen Sharp Demand, But ETH’s Price Action Shows Weak Follow-Through

November 4, 2025
Analyst Reveals What Ripple’s Latest Launch In The US Means For The XRP Price

Analyst Reveals What Ripple’s Latest Launch In The US Means For The XRP Price

November 4, 2025
What’s at Stake for Sam Bankman-Fried’s Long-awaited Appeal?

What’s at Stake for Sam Bankman-Fried’s Long-awaited Appeal?

November 4, 2025
Ripple Buys Palisade in $4B Investment Streak & Wallet Tokens like $BEST Could Explode

Ripple Buys Palisade in $4B Investment Streak & Wallet Tokens like $BEST Could Explode

November 4, 2025

Recent News

Ethereum Treasury Has Seen Sharp Demand, But ETH’s Price Action Shows Weak Follow-Through

Ethereum Treasury Has Seen Sharp Demand, But ETH’s Price Action Shows Weak Follow-Through

November 4, 2025
Analyst Reveals What Ripple’s Latest Launch In The US Means For The XRP Price

Analyst Reveals What Ripple’s Latest Launch In The US Means For The XRP Price

November 4, 2025

Categories

  • Altcoins
  • Bitcoin
  • Blockchain
  • Cryptocurrency
  • Dogecoin
  • Ethereum
  • Market
  • NFTs
  • Regualtions
  • XRP

Recommended

  • Ethereum Treasury Has Seen Sharp Demand, But ETH’s Price Action Shows Weak Follow-Through
  • Analyst Reveals What Ripple’s Latest Launch In The US Means For The XRP Price
  • What’s at Stake for Sam Bankman-Fried’s Long-awaited Appeal?
  • Ripple Buys Palisade in $4B Investment Streak & Wallet Tokens like $BEST Could Explode
  • Here’s Why The Bitcoin, Ethereum, And Dogecoin Prices Are Crashing Again

© 2025 SCRYPTO MAGAZINE | All Rights Reserved

No Result
View All Result
  • Home
  • Crypto
  • Bitcoin
  • Blockchain
  • Market
  • Ethereum
  • Altcoins
  • XRP
  • Dogecoin
  • NFTs
  • Regualtions

© 2025 SCRYPTO MAGAZINE | All Rights Reserved