Cursor 0day: When Full Disclosure Becomes the Only Protection Left
1–10 of 222 posts
Re: Cursor 0day: When Full Disclosure Becomes the Only Protection Left
#2Re: Cursor 0day: When Full Disclosure Becomes the Only Protection Left
#3Re: Cursor 0day: When Full Disclosure Becomes the Only Protection Left
#4Re: Cursor 0day: When Full Disclosure Becomes the Only Protection Left
#5I'm struggling to understand the process that went into this "feature" existing. It seems the most likely candidate is a developer's git started malfunctioning and an agent "fixed" it by dropping a `git.exe` in the repo and then conditionally calling it when it exists.
Re: Cursor 0day: When Full Disclosure Becomes the Only Protection Left
#6> 1. A vulnerability is reported.
> 2. A dialogue begins.
> 3. Severity is discussed.
> 4. Engineering teams investigate.
> 5. Fixes are developed.
> 6. Users are protected.
> 7. Public disclosure follows.
8. The author prompts an LLM to write a blog post.
9. HN users are wasting time, unsure which parts of the post come from the actual prompt, and which are hallucinated world knowledge slop.
Re: Cursor 0day: When Full Disclosure Becomes the Only Protection Left
#7Re: Cursor 0day: When Full Disclosure Becomes the Only Protection Left
#8You need to have an already malicious payload on your pc to make this exploit work (via clone/download/magic). I can understand the severity of the exploit but at the same time I’d hope to not have to run into this situation for it to happen in the first place
Re: Cursor 0day: When Full Disclosure Becomes the Only Protection Left
#9This report reads a bit like AI writing :/ You need to have an already malicious payload on your pc to make this exploit work (via clone/download/magic). I can understand the severity of the exploit but at the same time I’d hope to not have to run into this situation for it to happen in the first place
Re: Cursor 0day: When Full Disclosure Becomes the Only Protection Left
#10This report reads a bit like AI writing :/ You need to have an already malicious payload on your pc to make this exploit work (via clone/download/magic). I can understand the severity of the exploit but at the same time I’d hope to not have to run into this situation for it to happen in the first place
I find a github repo, I want to contribute to it. I clone it, open up cursor, make an edit, commit, and boom, I am infected.