Thursday, October 30, 2025
No Result
View All Result
Crypto Waffle
  • Home
  • Bitcoin
  • Crypto Updates
    • General
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
Marketcap
  • Home
  • Bitcoin
  • Crypto Updates
    • General
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
No Result
View All Result
Crypto Waffle
No Result
View All Result

Malicious Repos Can Trigger Auto Code Execution in Cursor

September 12, 2025
in Crypto Updates
Reading Time: 3 mins read
0 0
A A
0
Home Crypto Updates
Share on FacebookShare on Twitter


Enjoyed this article?

Share it with your friends!

Oasis Security has identified a vulnerability in Cursor, an AI-based code editor, that allows hidden code to run as soon as a user opens a project folder without any action or warning.

The issue comes from a default setting in Cursor. A safety feature called Workspace Trust is disabled by default when the program is first installed. As a result, certain task files can begin executing commands immediately when a developer opens a folder.

If a user adds a harmful task to a project and shares it online, those commands will run as soon as another person opens the folder in Cursor.

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

What are dApps in Crypto? (Explained with Animations)

What are dApps in Crypto? (Explained with Animations)
What are dApps in Crypto? (Explained with Animations)

Cursor is built on top of Visual Studio Code, which also includes the Workspace Trust feature. This tool is designed to protect developers from malicious code by blocking automatic tasks from unknown sources.

The vulnerability exploits the .vscode/tasks.json file, which can contain instructions to run tasks as soon as a folder is opened. Attackers can place these instructions in a shared project.

According to Erez Schwartz from Oasis Security, this behavior can lead to stolen credentials, changed files, or system access. It also increases the chances of supply chain attacks, where malicious code spreads through tools or projects used by many people.

To stay safe, users should take a few steps. First, they should enable Workspace Trust in Cursor to stop unknown tasks from running automatically. Second, it is advised to open untrusted projects using a different code editor, especially the .vscode folder, before using Cursor.

On August 28, Anthropic warned that bad actors are using its chatbot Claude to help carry out online crimes. How? Read the full story.



Source link

Tags: AutoCodeCursorExecutionMaliciousReposTrigger
Previous Post

Nicholas Galanin pulls out of Smithsonian event, claiming censorship

Next Post

California Bill to Regulate AI Chatbots Nears Decision

Related Posts

Live Trump Crypto Updates Today: Fed Cut Interest Rates as OFFICIAL TRUMP Surged 40%, and More…
Crypto Updates

Live Trump Crypto Updates Today: Fed Cut Interest Rates as OFFICIAL TRUMP Surged 40%, and More…

October 30, 2025
Behind the Vault Door: Tether Gold Attestation Report Reveals 375K Troy Ounces of Shine
Crypto Updates

Behind the Vault Door: Tether Gold Attestation Report Reveals 375K Troy Ounces of Shine

October 29, 2025
Ethereum’s Fusaka Upgrade Clears Final Test, Mainnet Next
Crypto Updates

Ethereum’s Fusaka Upgrade Clears Final Test, Mainnet Next

October 29, 2025
ASIC Confirms Stablecoins and Tokenised Assets Fall Under Financial Law
Crypto Updates

ASIC Confirms Stablecoins and Tokenised Assets Fall Under Financial Law

October 29, 2025
ETF Launch Countdown: Solana, Litecoin, and Hedera Set to List Despite U.S. Government Shutdown | Bitcoinist.com
Crypto Updates

ETF Launch Countdown: Solana, Litecoin, and Hedera Set to List Despite U.S. Government Shutdown | Bitcoinist.com

October 29, 2025
Grokipedia Goes Live, Claims to Tell ‘The Whole Truth’
Crypto Updates

Grokipedia Goes Live, Claims to Tell ‘The Whole Truth’

October 28, 2025
Next Post
California Bill to Regulate AI Chatbots Nears Decision

California Bill to Regulate AI Chatbots Nears Decision

REX-Osprey Solana ETF crosses 0M milestone as SOL hits seven-month high

REX-Osprey Solana ETF crosses $200M milestone as SOL hits seven-month high

Another Day, Another Record: Bitcoin’s Computing Muscle Flexes Harder

Another Day, Another Record: Bitcoin’s Computing Muscle Flexes Harder

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • USD
  • EUR
  • GBP
  • AUD
  • JPY
  • bitcoinBitcoin(BTC)
    $108,533.00
  • ethereumEthereum(ETH)
    $3,817.55
  • tetherTether(USDT)
    $1.00
  • binancecoinBNB(BNB)
    $1,097.11
  • rippleXRP(XRP)
    $2.50
  • solanaSolana(SOL)
    $187.63
  • usd-coinUSDC(USDC)
    $1.00
  • staked-etherLido Staked Ether(STETH)
    $3,819.99
  • dogecoinDogecoin(DOGE)
    $0.184257
  • tronTRON(TRX)
    $0.293122
Facebook Twitter Instagram Youtube RSS
Crypto Waffle

Your go-to source for the freshest cryptocurrency news, in-depth analysis, market trends, and expert insights.

CATEGORIES

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • NFT
  • Regulations
  • Scam Alert
  • Web3

SITEMAP

  • About us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Policy
  • Terms and Conditions
  • Contact Us

Copyright © 2025 Crypto Waffle.
Crypto Waffle is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Bitcoin
  • Crypto Updates
    • General
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis

Copyright © 2025 Crypto Waffle.
Crypto Waffle is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin(BTC)$108,533.00-4.05%
  • ethereumEthereum(ETH)$3,817.55-4.85%
  • tetherTether(USDT)$1.00-0.02%
  • binancecoinBNB(BNB)$1,097.11-1.44%
  • rippleXRP(XRP)$2.50-5.75%
  • solanaSolana(SOL)$187.63-5.51%
  • usd-coinUSDC(USDC)$1.000.00%
  • staked-etherLido Staked Ether(STETH)$3,819.99-4.81%
  • dogecoinDogecoin(DOGE)$0.184257-5.89%
  • tronTRON(TRX)$0.293122-1.38%

Powered by
...
►
Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
None
►
Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
None
►
Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
None
►
Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
None
►
Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
None
Powered by