• Dapps:16.23K
  • Blockchains:78
  • Active users:66.47M
  • 30d volume:$303.26B
  • 30d transactions:$879.24M

Vulnerability in Cursor: New Cyber Threats for Developers

user avatar

by Giorgi Kostiuk

2 days ago


Recent cybersecurity research has uncovered a new vulnerability in the programming AI tool Cursor, which is used by Coinbase. This vulnerability allows attackers to hide malicious instructions in standard developer files.

What is the CopyPasta License Attack?

Cybersecurity firm HiddenLayer discovered a vulnerability termed the 'CopyPasta License Attack'. This vulnerability enables hackers to embed malicious instructions in standard developer files such as LICENSE.txt and README.md. The injections, delivered as prompt injections in markdown comments, trick the AI into recognizing them as essential, allowing harmful code to be silently spread across an organization’s codebase.

Risks for Developers

By disguising the virus as a critical license file comment, attackers can quickly distribute malicious payloads with minimal user interaction. The potential implications are severe, including the creation of backdoors, theft of confidential data, and corruption of critical files vital for both development and production environments.

Overall Impact on AI Tools

HiddenLayer's tests demonstrated that Cursor automatically copied the infected prompt injections to new files it created, showcasing the ease with which malware can propagate via this exploit. Importantly, this threat is not limited to Cursor. Other AI programming tools, including Windsurf, Kiro, and Aider, have also been reported to share this vulnerability, emphasizing the growing cybersecurity challenge in AI-assisted software development.

This vulnerability raises serious questions about the security of using AI tools in programming and the need for rigorous scanning and approval processes to safeguard codebases.

0

Rewards

chest
chest
chest
chest

More rewards

Discover enhanced rewards on our social media.

Other news

Ethereum: Why Predictions of a Move to $7,500 Are Becoming Reality

chest

Ethereum is moving towards $7,500 due to increasing institutional interest and staking rewards.

user avatarGiorgi Kostiuk

September Volatility in Bitcoin Driven by Institutional Flows and ETF Activity

chest

In September 2025, Bitcoin shows typical fluctuations shaped by institutional flows and ETF dynamics.

user avatarGiorgi Kostiuk

Token Unlocks for Cheelee, Aptos, and Sonic: What to Expect?

chest

Next week, major token unlocks for Cheelee, Aptos, and Sonic could impact the cryptocurrency market significantly.

user avatarGiorgi Kostiuk

Cryptocurrency Market: Bitcoin Steady, Dogwifhat Displays Signs of Upside

chest

As Bitcoin consolidates and Ethereum retreats, Dogwifhat (WIF) shows signs of potential growth amid market volatility.

user avatarGiorgi Kostiuk

CryptoAppsy: An Innovative Tool for Traders and Investors

chest

The accessible CryptoAppsy app will inform users of market changes and provide real-time data.

user avatarGiorgi Kostiuk

Bitcoin on September 8: Concerning Figures from Analyst Timothy Peterson

chest

Timothy Peterson shared data on Bitcoin's performance on September 8, highlighting risks for investors.

user avatarGiorgi Kostiuk

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.