Anysphere · Cursor · CVE-2026-63093
**Name of the Vulnerable Software and Affected Versions**
Cursor for Windows version 3.2.16
**Description**
A binary planting issue allows remote attackers to achieve arbitrary code execution. This occurs when a developer clones and opens a crafted repository containing a malicious `git.exe` file in the root directory. The IDE automatically resolves and executes this workspace-resident `git.exe` during startup and on a recurring timed cadence without user interaction, running the binary with the privileges of the current user.
**Recommendations**
Update Cursor for Windows to a version newer than 3.2.16.