HabrAugust 8, 2026🇷🇺Translated from Russian

RCE Vulnerability in AI Code Editors Cursor, VS Code and Google Antigravity Threatens 50 Million Developers

Researchers at AISLE have disclosed a critical remote code execution vulnerability that affected the popular AI code editors Cursor, Microsoft Visual Studio Code and Google Antigravity. The flaw enabled an attacker to execute arbitrary code on a developer’s machine simply by embedding a malicious link inside a Git commit message. Approximately 50 million users were potentially at risk before patches were issued by all three vendors.

How the attack worked

The exploitation scenario closely mirrored normal development workflows. An attacker only needed to place a crafted link in a commit message. When a developer viewed the commit history inside the IDE and clicked the link, arbitrary code executed with the privileges of the current user. No pop-ups, confirmation dialogs or other indicators appeared during execution.

Successful exploitation allowed an attacker to:

  • Steal API keys for services such as OpenAI, Anthropic and Stripe
  • Install persistent malware that survived editor restarts
  • Read or delete files on the local filesystem
  • Run any commands under the logged-in user account

Why multiple editors were affected

Cursor was built as a fork of Visual Studio Code and inherited its architecture. The same underlying issue was later found in Google Antigravity, which also relies on VS Code components. This demonstrates the “shared component vulnerability” effect: when many AI tools reuse the same foundation, a single architectural flaw can propagate across multiple widely used products.

Why developers are high-value targets

Developer workstations typically contain corporate Git repositories, API and SSH keys, Kubernetes credentials and environment secrets. Compromising one machine often provides an initial foothold into broader corporate infrastructure. AI editors increase this risk by concentrating even more sensitive data and automation capabilities in a single environment.

Practical recommendations

Organizations using the affected editors should:

  • Update to the latest patched versions immediately
  • Scan developer workstations for suspicious activity
  • Rotate any API keys, tokens or credentials that may have been stored locally
  • Treat repository contents, including commit messages, as potentially untrusted
  • Review AI-generated code and actions with heightened scrutiny

Related articles

HabrVulnerabilities & Exploits

NEOMSA APIM 4.6.0 Eliminates All Critical and High Vulnerabilities Registered in FSTEC BDU

Neoflex has released NEOMSA APIM 4.6.0 with a primary focus on strengthening the security of the platform's supply chain. The team generated an SBOM in CycloneDX format, scanned components and dependencies using Grype, and cross-referenced findings against the FSTEC BDU database. This process reduced total registered vulnerabilities from 57 to 7, completely removing all 10 Critical and 24 High issues. The platform now meets the formal Security Gate criterion requiring zero Critical or High vulnerabilities from the FSTEC database in the final build. Remaining Medium findings are documented and tracked for future updates. The release provides customers with a verified, transparent component inventory that simplifies compliance and integration reviews.

Security NEXTVulnerabilities & Exploits

Cisco Publishes 12 Security Advisories Fixing Critical Flaws in Catalyst SD-WAN and IOS XE

Cisco Systems released 12 new security advisories on August 5, 2026, disclosing a total of 23 vulnerabilities across multiple products. Two advisories covering Cisco Catalyst SD-WAN Software and Cisco IOS XE Software received the highest Critical severity rating. The SD-WAN advisory addresses five issues, including CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310, each scoring 9.9 on CVSSv3.1. The IOS XE advisory details seven vulnerabilities, with CVE-2026-20272 rated 9.8 and CVE-2026-20267 rated 9.0. Additional advisories cover flaws in Integrated Management Controller, RoomOS, and Terminal Services Agent. Organizations are urged to apply the hardening releases immediately to mitigate remote exploitation risks.

AntiMalwareVulnerabilities & Exploits

Head Mare Hackers Exploit TrueConf Servers to Distribute PhantomCore and PhantomGraph Backdoors

Russian organizations have been targeted in a new campaign by the Head Mare group, which compromises unpatched TrueConf servers to deliver backdoors. Attackers chain vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with maximum privileges on affected servers. They then replace a server file with a web shell to explore the victim's infrastructure, access the TrueConf database, and substitute the client installer. Victims are tricked via social engineering into downloading the malicious client during video conferences without any suspicious emails. The campaign affects TrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, and earlier releases. Kaspersky researchers recommend immediate updates to patched versions 5.3.9, 5.4.9, and 5.5.5 released on 18 June 2026. The threat extends beyond direct TrueConf users, as any employee invited to a compromised server can inadvertently install the backdoor.

HispasecVulnerabilities & Exploits

Zapscape Flaw in KVM Breaks Nested Virtualization Isolation Allowing L1 Guest Root Code Execution on Linux Host

The Zapscape vulnerability (CVE-2026-64561) affects KVM/x86 in the Linux kernel and enables an attacker with kernel privileges inside an L1 virtual machine to escape to the host and execute code as root. The flaw occurs in the shadow MMU when handling page faults for nested guests, specifically due to an incorrect order of stale root condition checks that leads to a use-after-free condition. This weakens the isolation between the host and L1 guests precisely when nested virtualization is enabled for potentially untrusted tenants. A public proof-of-concept demonstrates the escape by creating a file named /Zapscape owned by root on the host. The issue impacts Linux kernels starting from version 5.9, with fixes already merged into stable branches including 6.6.148, 6.12.101, 6.18.42, 7.1.6 and 7.2 rc5. On Intel systems the attack requires EPT page walk lengths 4 and 5 to be exposed to the L1 guest, while no equivalent condition is documented for AMD. Organizations are advised to apply patches promptly or disable nested virtualization for untrusted workloads.