• Dapps:16.23K
  • Blockchains:78
  • Active users:66.47M
  • 30d volume:$303.26B
  • 30d transactions:$879.24M

Vulnerability in Cursor: New Cyber Threats for Developers

user avatar

by Giorgi Kostiuk

2 hours ago


Recent cybersecurity research has uncovered a new vulnerability in the programming AI tool Cursor, which is used by Coinbase. This vulnerability allows attackers to hide malicious instructions in standard developer files.

What is the CopyPasta License Attack?

Cybersecurity firm HiddenLayer discovered a vulnerability termed the 'CopyPasta License Attack'. This vulnerability enables hackers to embed malicious instructions in standard developer files such as LICENSE.txt and README.md. The injections, delivered as prompt injections in markdown comments, trick the AI into recognizing them as essential, allowing harmful code to be silently spread across an organization’s codebase.

Risks for Developers

By disguising the virus as a critical license file comment, attackers can quickly distribute malicious payloads with minimal user interaction. The potential implications are severe, including the creation of backdoors, theft of confidential data, and corruption of critical files vital for both development and production environments.

Overall Impact on AI Tools

HiddenLayer's tests demonstrated that Cursor automatically copied the infected prompt injections to new files it created, showcasing the ease with which malware can propagate via this exploit. Importantly, this threat is not limited to Cursor. Other AI programming tools, including Windsurf, Kiro, and Aider, have also been reported to share this vulnerability, emphasizing the growing cybersecurity challenge in AI-assisted software development.

This vulnerability raises serious questions about the security of using AI tools in programming and the need for rigorous scanning and approval processes to safeguard codebases.

0

Rewards

chest
chest
chest
chest

More rewards

Discover enhanced rewards on our social media.

Other news

Yingyu Universe Confirms HKD 300 Million Investment in Guofu Quantum for Digital Economy Growth

chest

Yingyu Universe has confirmed its investment in Guofu Quantum to advance initiatives in the digital economy and Web3.

user avatarGiorgi Kostiuk

Solana Rises 30% Amid ETF Hopes and Alpenglow Upgrade

chest

Solana has risen 30% in a month but struggles at the $215 resistance level. A potential ETF approval could change everything.

user avatarGiorgi Kostiuk

Closure of Dot App: Challenges for AI Technologies and Their Safety

chest

Dot app ceases operations due to founders' internal disagreements, raising issues of AI safety and ethical standards.

user avatarGiorgi Kostiuk

Itaú Asset Creates Crypto Division Led by João Marco Braga da Cunha

chest

Itaú Asset Management, Brazil's largest private asset manager, has created a new cryptocurrency division led by João Marco Braga da Cunha.

user avatarGiorgi Kostiuk

Rising Institutional Interest in SUI Token: Insights and Forecasts

chest

Institutional investments and technical indicators of the SUI token suggest growth and possible breakout from key levels.

user avatarGiorgi Kostiuk

President Trump Shifts Financial Landscape in Favor of Cryptocurrencies

chest

President Trump's actions in 2025 boost crypto firms, overtaking banks and reshaping the U.S. financial landscape.

user avatarGiorgi Kostiuk

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.