Cursor and Google: 1-Click RCE Vulnerability in Cursor, VS Code, and Google Antigravity Lets Attackers Execute Arbitrary Code

Cursor and Google: 1-Click RCE Vulnerability in Cursor, VS Code, and Google Antigravity Lets Attackers Execute Arbitrary Code

Critical One-Click RCE Flaw in Cursor, VS Code, and Google Antigravity Exposed

A severe one-click remote code execution (RCE) vulnerability was discovered in Cursor, Microsoft Visual Studio Code (VS Code), and Google Antigravity, exposing developers to potential endpoint compromise. The flaw, identified by security firm AISLE in late 2025, allowed attackers to embed malicious commands in commit message links, which executed arbitrary code when clicked without warnings or user approval.

The vulnerability posed a significant risk, as developer environments often store sensitive assets, including source code, cloud credentials, API tokens, SSH keys, and deployment scripts. Exploitation could grant attackers terminal-level privileges, enabling data exfiltration, file deletion, malware installation, or follow-on attacks like keyloggers to capture credentials.

The attack leveraged trusted commit messages, a common part of version-control workflows, making social engineering easier. AISLE’s automated detection system flagged the issue in VS Code, which shares its codebase with Cursor, and later in Google Antigravity. After responsible disclosure, Microsoft, Cursor, and Google patched the flaw by 2026, though the vulnerability persisted for months before remediation.

The incident underscores the growing security risks in AI-assisted coding tools, where minor flaws in link handling can lead to major breaches. With code editors serving as gateways to repositories, terminals, and secrets management, even routine actions like reviewing commits can become attack vectors. Organizations were advised to update affected software to mitigate exposure.

Source: https://gbhackers.com/1-click-rce-vulnerability-in-cursor-vs-code-and-google-antigravity/

Anysphere cybersecurity rating report: https://www.rankiteo.com/company/anysphereinc

Google Antigravity cybersecurity rating report: https://www.rankiteo.com/company/google-antigravity

"id": "ANYGOO1785911190",
"linkid": "anysphereinc, google-antigravity",
"type": "Vulnerability",
"date": "10/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Technology/Development Tools',
                        'name': 'Cursor',
                        'type': 'Software'},
                       {'industry': 'Technology/Development Tools',
                        'name': 'Microsoft Visual Studio Code (VS Code)',
                        'type': 'Software'},
                       {'industry': 'Technology/Development Tools',
                        'name': 'Google Antigravity',
                        'type': 'Software'}],
 'attack_vector': 'Malicious commit message links',
 'data_breach': {'data_exfiltration': 'Potential',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': 'Source code, cloud credentials, '
                                             'API tokens, SSH keys, deployment '
                                             'scripts'},
 'date_detected': '2025',
 'date_resolved': '2026',
 'description': 'A severe one-click remote code execution (RCE) vulnerability '
                'was discovered in Cursor, Microsoft Visual Studio Code (VS '
                'Code), and Google Antigravity, exposing developers to '
                'potential endpoint compromise. The flaw allowed attackers to '
                'embed malicious commands in commit message links, which '
                'executed arbitrary code when clicked without warnings or user '
                'approval. The vulnerability posed a significant risk as '
                'developer environments often store sensitive assets, '
                'including source code, cloud credentials, API tokens, SSH '
                'keys, and deployment scripts. Exploitation could grant '
                'attackers terminal-level privileges, enabling data '
                'exfiltration, file deletion, malware installation, or '
                'follow-on attacks like keyloggers to capture credentials.',
 'impact': {'data_compromised': 'Source code, cloud credentials, API tokens, '
                                'SSH keys, deployment scripts',
            'operational_impact': 'Potential terminal-level compromise, '
                                  'malware installation, data exfiltration, '
                                  'file deletion',
            'systems_affected': 'Developer environments, endpoints'},
 'initial_access_broker': {'entry_point': 'Malicious commit message links'},
 'investigation_status': 'Resolved',
 'lessons_learned': 'The incident underscores the growing security risks in '
                    'AI-assisted coding tools, where minor flaws in link '
                    'handling can lead to major breaches. Even routine actions '
                    'like reviewing commits can become attack vectors.',
 'post_incident_analysis': {'corrective_actions': 'Patching the vulnerability '
                                                  'and releasing software '
                                                  'updates',
                            'root_causes': 'Flaw in link handling in commit '
                                           'messages'},
 'recommendations': 'Organizations were advised to update affected software to '
                    'mitigate exposure.',
 'references': [{'source': 'AISLE'}],
 'response': {'containment_measures': 'Patching the vulnerability',
              'remediation_measures': 'Software updates released by Microsoft, '
                                      'Cursor, and Google',
              'third_party_assistance': 'AISLE (security firm)'},
 'title': 'Critical One-Click RCE Flaw in Cursor, VS Code, and Google '
          'Antigravity Exposed',
 'type': 'Remote Code Execution (RCE)',
 'vulnerability_exploited': 'One-click RCE flaw in link handling'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.