MarsCode A.I CyberSecurity Scoring
MarsCode
Company Information
Website:https://marscode.com/?utm_source=linkedin
Employees number:1
Number of followers:0
NAICS:5112
Industry Type:Software Development
Homepage:marscode.com
MarsCode Risk Score (AI oriented)
Between 750 and 799
MarsCodeSoftware Development
Updated:
19/08/2026
19/08/2026
780/1000
Fair
Baa
MarsCode Global Score (TPRM)
xxxx
MarsCodeSoftware Development
Score locked

MarsCodeFair
Current Score
780Baa (FAIR)
01000
1 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
780
AUGUST 2026
780
JULY 2026
782
Vulnerability
13 Jul 2026 • MarsCode
Windsurf, Cursor and Trae IDE: Critical Cursor 0-day Vulnerability Enables Arbitrary Code Execution Attacks
Cursor IDE Binary Planting Flaw Enables Zero-Click Code Execution
780
CRITICAL-2
MARANYAMA1787135211
Cursor IDE Binary Planting Flaw Enables Zero-Click Code Execution
A critical binary planting vulnerability in the Cursor IDE (CVE-2026-63093, CVSS 8.7) allows attackers to execute arbitrary code when a developer opens a malicious repository on Windows. The flaw, disclosed by Mindgard on July 14, 2026, stems from Cursor’s method of locating the `git.exe` binary during project loading.
When opening a repository, Cursor searches for `git.exe` in multiple locations, including the workspace root. If a malicious file named `git.exe` is planted there and no legitimate binary exists in trusted system paths Windows executes the attacker’s file automatically under the logged-in user’s privileges. The attack requires no user interaction, prompts, or prior access to the victim’s machine.
Mindgard demonstrated the flaw by replacing `git.exe` with a renamed Windows Calculator app, which launched immediately upon opening the repository. The issue extends beyond `git.exe`: Cursor also searches for `hatch.exe` when a `pyproject.toml` file is present, using the same insecure resolution logic. Unlike more conspicuous execution methods (e.g., `tasks.json`), `pyproject.toml` files appear benign, making this a stealthier attack vector.
Workspace Trust, a security feature meant to block execution in untrusted folders, proved ineffective. Testing on Trae IDE (which enables Workspace Trust by default) showed the IDE still attempts to locate `git.exe` in untrusted workspaces. Cursor ships with Workspace Trust disabled by default, meaning code execution can occur without any user confirmation when opening a folder.
The vulnerability was reported to Cursor on December 15, 2025, but the company initially dismissed it as out of scope for its bug bounty program, citing a shared-responsibility model. Cursor later addressed the issue on July 13, 2026, just before Mindgard’s public disclosure though no formal security advisory was issued.
The flaw is part of a broader attack surface in AI-powered IDEs, including unpatched Chromium vulnerabilities in outdated Electron builds affecting Cursor and Windsurf, impacting an estimated 1.8 million developers. Other recent Cursor vulnerabilities, such as CVE-2026-50548 and CVE-2026-50549 (DuneSlide), enabled sandbox escape and OS-level remote code execution via prompt injection, patched in Cursor 3.0.
The incident highlights risks in binary resolution logic and the assumption that only specific filenames (e.g., `git.exe`) pose threats. Attackers can exploit any executable file in a workspace if it aligns with the IDE’s search behavior.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
JUNE 2026
782
MAY 2026
782
APRIL 2026
782
MARCH 2026
782
FEBRUARY 2026
782
JANUARY 2026
782
DECEMBER 2025
782
NOVEMBER 2025
782
OCTOBER 2025
782
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for MarsCode ??
What was MarsCode's A.I Rankiteo Cyber Score in August 2026 ??
What was MarsCode's A.I Rankiteo Cyber Score in July 2026 ??
What was MarsCode's A.I Rankiteo Cyber Score in June 2026 ??
What was MarsCode's A.I Rankiteo Cyber Score in May 2026 ??
What was MarsCode's A.I Rankiteo Cyber Score in April 2026 ??
What was MarsCode's A.I Rankiteo Cyber Score in March 2026 ??
What was MarsCode's A.I Rankiteo Cyber Score in February 2026 ??
What was MarsCode's A.I Rankiteo Cyber Score in January 2026 ??
What was MarsCode's A.I Rankiteo Cyber Score in December 2025 ??
What was MarsCode's A.I Rankiteo Cyber Score in November 2025 ??
What was MarsCode's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on MarsCode's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with MarsCode ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view MarsCode's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?