Security researcher discloses 0-day vulnerability in Cursor, cites lack of vendor response

According to Mindgard, a security researcher disclosed a 0-day vulnerability in Cursor, with the publication arguing that full disclosure became necessary due to lack of proper vendor response. The disclosure highlights growing security concerns around AI coding assistants.

Update (2026-07-22): According to CSO Online, Pillar Security disclosed that AI coding agents in Cursor, Codex, Gemini CLI, and Antigravity can indirectly cross security boundaries without technically escaping their sandboxes, instead relying on writing content for trusted components outside the sandbox to later execute. The researchers identified four specific and rep...

Topics

AI securityAgentic AICursorGemini

Sources

Go deeper

This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.