Overview
Security failures when AI coding IDEs auto-trust workspace content — MCP poisoning, agentjacking, worms, and classic binary search-path RCE — turning “clone and open” into an attack surface.
Timeline
- 2026-06: agentjacking, miasma-worm campaigns against coding agents
- 2026-07-09: GhostApproval symlink issues in Cursor
- 2026-07-14: cursor-git-exe-rce full disclosure (7 months unpatched) (2026-07-17-cursor-git-exe-mindgard-primary)
Key Players
Analysis
Agent autonomy amplifies traditional IDE trust bugs. Disclosure latency and “out of scope” triage are becoming part of the story alongside the CVEs themselves.