Critical One-Click RCE Flaw Exposes VS Code and Cursor Users to Remote Code Execution

A critical one-click remote code execution (RCE) flaw has been disclosed in popular AI editors Cursor, VS Code, and Antigravity. The bug allows attackers to embed malicious commands in links within commit messages, which can be executed with a single click. This changes the trust boundary from the network to the editor itself, making it a significant security concern. Users should be cautious when clicking links within commit messages and consider implementing additional security measures.

Source →
FeedLens — Signal over noise Last 7 days