Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
MarsCode

MarsCode Vendor Cyber Rating & Cyber Score

marscode.com

MarsCode is an AI-powered Cloud IDE (Integrated Development Environment). The built-in AI Assistant and the out-of-the-box development environment let you focus more on the development of various projects. For those who still want to use their local IDE, we also provide IDE extensions which support 100+ programming languages and mainstream IDEs, providing suggestions for writing single lines of code or entire functions during the coding process. Additionally, it supports auxiliary features such as code explanations, code reviews, and issue fixes, enhancing coding efficiency and quality.


MarsCode A.I CyberSecurity Scoring

MarsCode
Company Information
Website:https://marscode.com/?utm_source=linkedin
Employees number:1
Number of followers:0
NAICS:5112
Industry Type:Software Development
Homepage:marscode.com
MarsCode Risk Score (AI oriented)
Between 750 and 799
logo
MarsCodeSoftware Development
Updated:
19/08/2026
780/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
MarsCode Global Score (TPRM)
xxxx
logo
MarsCodeSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

MarsCode
MarsCodeFair
Current Score
780Baa (FAIR)
01000
1 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
780Before Incident
AUGUST 2026
780Before Incident
JULY 2026
782Before Incident
Vulnerability
13 Jul 2026MarsCode
Windsurf, Cursor and Trae IDE: Critical Cursor 0-day Vulnerability Enables Arbitrary Code Execution Attacks

Cursor IDE Binary Planting Flaw Enables Zero-Click Code Execution

780After Incident
CRITICAL-2
MARANYAMA1787135211
Cursor IDE Binary Planting Flaw Enables Zero-Click Code Execution A critical binary planting vulnerability in the Cursor IDE (CVE-2026-63093, CVSS 8.7) allows attackers to execute arbitrary code when a developer opens a malicious repository on Windows. The flaw, disclosed by Mindgard on July 14, 2026, stems from Cursor’s method of locating the `git.exe` binary during project loading. When opening a repository, Cursor searches for `git.exe` in multiple locations, including the workspace root. If a malicious file named `git.exe` is planted there and no legitimate binary exists in trusted system paths Windows executes the attacker’s file automatically under the logged-in user’s privileges. The attack requires no user interaction, prompts, or prior access to the victim’s machine. Mindgard demonstrated the flaw by replacing `git.exe` with a renamed Windows Calculator app, which launched immediately upon opening the repository. The issue extends beyond `git.exe`: Cursor also searches for `hatch.exe` when a `pyproject.toml` file is present, using the same insecure resolution logic. Unlike more conspicuous execution methods (e.g., `tasks.json`), `pyproject.toml` files appear benign, making this a stealthier attack vector. Workspace Trust, a security feature meant to block execution in untrusted folders, proved ineffective. Testing on Trae IDE (which enables Workspace Trust by default) showed the IDE still attempts to locate `git.exe` in untrusted workspaces. Cursor ships with Workspace Trust disabled by default, meaning code execution can occur without any user confirmation when opening a folder. The vulnerability was reported to Cursor on December 15, 2025, but the company initially dismissed it as out of scope for its bug bounty program, citing a shared-responsibility model. Cursor later addressed the issue on July 13, 2026, just before Mindgard’s public disclosure though no formal security advisory was issued. The flaw is part of a broader attack surface in AI-powered IDEs, including unpatched Chromium vulnerabilities in outdated Electron builds affecting Cursor and Windsurf, impacting an estimated 1.8 million developers. Other recent Cursor vulnerabilities, such as CVE-2026-50548 and CVE-2026-50549 (DuneSlide), enabled sandbox escape and OS-level remote code execution via prompt injection, patched in Cursor 3.0. The incident highlights risks in binary resolution logic and the assumption that only specific filenames (e.g., `git.exe`) pose threats. Attackers can exploit any executable file in a workspace if it aligns with the IDE’s search behavior.
INCIDENT DETAILS -
TYPE
Binary Planting Vulnerability
IMPACT
Systems Affected: Cursor IDE on Windows systemsOperational Impact: Arbitrary code execution under user privilegesBrand Reputation Impact: Potential reputational damage due to security flaws in a developer tool
JUNE 2026
782Before Incident
MAY 2026
782Before Incident
APRIL 2026
782Before Incident
MARCH 2026
782Before Incident
FEBRUARY 2026
782Before Incident
JANUARY 2026
782Before Incident
DECEMBER 2025
782Before Incident
NOVEMBER 2025
782Before Incident
OCTOBER 2025
782Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for MarsCode ?
?
What was MarsCode's A.I Rankiteo Cyber Score in August 2026 ?
?
What was MarsCode's A.I Rankiteo Cyber Score in July 2026 ?
?
What was MarsCode's A.I Rankiteo Cyber Score in June 2026 ?
?
What was MarsCode's A.I Rankiteo Cyber Score in May 2026 ?
?
What was MarsCode's A.I Rankiteo Cyber Score in April 2026 ?
?
What was MarsCode's A.I Rankiteo Cyber Score in March 2026 ?
?
What was MarsCode's A.I Rankiteo Cyber Score in February 2026 ?
?
What was MarsCode's A.I Rankiteo Cyber Score in January 2026 ?
?
What was MarsCode's A.I Rankiteo Cyber Score in December 2025 ?
?
What was MarsCode's A.I Rankiteo Cyber Score in November 2025 ?
?
What was MarsCode's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on MarsCode's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with MarsCode ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view MarsCode's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?