CVE-2026-35603: Cursor Still Trusts a World-Writable Folder
This story is from 2026-08-27. It is preserved in the archive; the latest stories are on the live feed.
TL;DR Claude Code, Cursor, Codex CLI and Gemini CLI on Windows all load machine-wide configuration from C:\ProgramData\ , a folder any standard user can write to. Anyone with a normal account can plant a hooks file there and have their command run under every other user who launches the tool, admin…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-08-27 18:49 · DEV Community — AI
CVE-2026-35603: Cursor Still Trusts a World-Writable Folder