AISLE Discovers a One-Click RCE Vulnerability in Cursor, VS Code, and Google Antigravity

Author

Stanislav Fort

Published

Cursor blog hero image

See what AISLE can find and fix autonomously in your own code.

Sovereign AI CybersecurityTalk to Us

AISLE’s AI analyzer discovered a one-click remote command execution (RCE) vulnerability in Cursor, VS Code, and Google Antigravity, which are the developer tools 50 million software engineers trust to create code. In all three of these code editors, malicious commands could be hidden within links found in commit messages. By clicking on them, you would unknowingly trigger data exfiltration, install persistent malware, or delete files.

In other words, this vulnerability allowed attackers to do whatever they wanted on your laptop. It has since been fixed across all three platforms.

From a Single Click to Total Compromise

Here’s how it worked: if you clicked on a malicious link, no pop-up warning would appear. Instead, the code editors executed arbitrary code without prompting users for confirmation. There was no way to know that the code had executed, and it gave the attacker full terminal privileges. An attacker could easily use it to:

  • Exfiltrate sensitive data, such as API keys (OpenAI, Anthropic, and Stripe)
  • Install persistent malware, such as keyloggers that broadcast terminal input to external servers
  • Crawl the local file system or delete files

Three Platforms, One Vulnerability

When the AISLE Research Team ran automated vulnerability detection on developer tooling in fall 2025, AISLE’s analyzer agents found this critical vulnerability in VS Code. Because Cursor is built on VS Code, the issue appeared in Cursor as well. AISLE responsibly disclosed the issue to both Microsoft and Cursor as soon as our AI system flagged it. However, the issue persisted into 2026, when it made its way into Google Antigravity, Google’s AI-assisted coding environment. We immediately reported it to Google.

As soon as they received our disclosures, Google and Cursor fixed the issue. Microsoft remediated it in VS Code somewhat later, so it is no longer present on the current versions of any of these platforms. We recommend updating to the latest version to ensure you are not affected.

Getting Ahead of AI-Powered Threats with AISLE

To see what AISLE finds in your codebase, get a one-time AI code audit: Snapshot. Snapshot delivers AISLE’s industry-leading detection and triage capability in any deployment environment, including air-gapped networks, in hours. Get your Snapshot.

Keep reading

More from AISLE

FeaturedResearchAISLE Discovered Six curl CVEs After OpenAI and Anthropic Found ZeroAfter frontier AI systems came up empty, AISLE surfaced six CVEs in curl, one of the world's most audited codebases. Its maintainers patched all six.Stanislav FortSeptember 2, 2026ResearchAISLE Discovers 6 High and Critical CVEs in FFmpegAISLE's AI-native engine found six high and critical CVEs in FFmpeg, including a 9.8 remote heap overflow and a stack overflow that survived 19 years.AISLE Research Team August 27, 2026ResearchAttackers Are Using AI to Find Vulnerabilities in Your Code. Your SAST Was Never Even Looking for ThemCan AI-native code analysis replace SAST, or is it just a complement. Here's what data from real-world results shows.Ondrej VlcekAugust 12, 2026ResearchAISLE Finds 21 Security Issues in FFmpeg, Including 6 New CVEsAISLE uncovered 21 issues in FFmpeg, including 6 new CVEs spanning code execution and out-of-bounds reads. All patched, with commit links inside.AISLE Research Team August 5, 2026ResearchThe Model That Fixes Your Code Might Hack the Linux KernelLearn how easy it is to trojanize a model, and what defenders can do to protect their supply chains from this emerging threat.Patrik MadaJuly 28, 2026PerspectivesThe Economics of Security Vulnerabilities: Why Discovery Is Not CommoditizingIf discovery is cheap, why are people willing to pay more for exploits than ever before? Here's what the market for exploits shows.Ondrej VlcekJuly 23, 2026ResearchAISLE Finds 8 CVEs Across MySQL, MariaDB, and PostgreSQLLearn how AISLE found 8 CVEs in critical databases using autonomous, AI-native analysis and verification.AISLE Research Team July 7, 2026ResearchAISLE Discovers 6 New CVEs in curl, Including the Oldest Issue Ever ReportedAISLE's analyzer discovered 6 new CVEs in curl, more than 2x the nearest AI security platform and including the oldest security issue in the project.AISLE Research Team June 24, 2026