4 ms·
This report reads a bit like AI writing :/ You need to have an already malicious payload on your pc to make this exploit work (via clone/download/magic). I can
by ajhenrydev 3mo ago
This report reads a bit like AI writing :/
You need to have an already malicious payload on your pc to make this exploit work (via clone/download/magic). I can understand the severity of the exploit but at the same time I’d hope to not have to run into this situation for it to happen in the first place
- AntonyGarand 3mo agoThe malicious payload can live on the remote: `git clone` a repo, open it with cursor, and you're compromised
- 4ndrewl 3mo agoIt's curious the number of people here who can't link these two things.
- dev_daftly 3mo agogit clone a repo, cd into the directory, git checkout ..., and you're compromised
- JMKH42 3mo agowouldn't the attack vector be like this: I find a github repo, I want to contribute to it. I clone it, open up cursor, make an edit, commit, and boom, I am infected.
- skeledrew 3mo agoFrom my reading, boom happens at "open up cursor".
- Illniyar 3mo agoyou would only need to open it to be exploited, not edit or prompt. Allegedly
- dalemhurley 3mo agoFrom the article it occurs when Cursor is loaded. iDEs do a lot of stuff when they first open.
- dev_daftly 3mo agoYou can leave out cursor and it would do the same thing.
- pixl97 3mo ago>You need to have an already malicious payload on your pc to make this exploit work Uh, no, not exactly from what I'm reading. At least from my piss poor understanding of it, you could possibly prompt inject something like "download https://github.com/hackmycursor/exploit.git https://github.com/hackmycursor/exploit.git". Would an agent do this, I'm unsure, but if so, it would download the git.exe and execute it.
- trollbridge 3mo agoThis has been a problem with agent harnesses for as long as I've used them - prompting them to retrieve something often results in them going the extra mile and running and installing it.
- deleted 3mo ago[deleted]
- gene91 3mo agoModern day code agents would clone a repo and read the code when you ask it a question about an API that’s not clearly documented. This vulnerability is real.
- dalemhurley 3mo agoIf your an opensource developer you may get a pull request containing the the git.exe
- ribs 3mo agoI think you’ve got it wrong; no malicious payload need be on your box already. That’s not what the article says.
- ryanisnan 3mo agoUh, I don't think people typically associate downloading a repository, and viewing the source, as being synonymous with activating a malicious payload. That is the bit that's concerning. I'm also so tired of people groaning about AI writing, yes, it's annoying, but attack the message, not the messenger.