AINewsnow

CVE-2026-35603: Cursor Still Trusts a World-Writable Folder

This story is from 2026-08-27. It is preserved in the archive; the latest stories are on the live feed.

TL;DR Claude Code, Cursor, Codex CLI and Gemini CLI on Windows all load machine-wide configuration from C:\ProgramData\ , a folder any standard user can write to. Anyone with a normal account can plant a hooks file there and have their command run under every other user who launches the tool, admin…

Read the full story at DEV Community — AI ↗

Timeline · 1 report

  1. 2026-08-27 18:49 · DEV Community — AI
    CVE-2026-35603: Cursor Still Trusts a World-Writable Folder

More stories

  1. AI skills — r/AI_Agents
  2. Plugin4Shell and NIST IR 8587, days apart: what actually authorizes an AI agent’s action? — r/AI_Agents
  3. Pay $39.99 once to put ChatGPT, Claude, Gemini, and more in a single workspace for life — Mashable AI
  4. A zero-click RCE flaw in AI coding agents could have exposed enterprise systems — InfoWorld AI
  5. Choosing a Coding Agent Model: Claude Opus 5, GPT-5.6 Sol, or Gemini 3.7 Flash — DEV Community — AI
  6. Gemini self-censors in a harmful, obscure way — r/GeminiAI
  7. I gave 6 different AIs the same 5 questions — r/AI_Agents
  8. What does AI forgetting context actually look like for you? — r/AI_Agents

Get the daily brief of stories like this at 6:30 every morning →