One-Click RCE Flaw Disclosed in VS Code, Cursor, and Google Antigravity Editors
A remote code execution vulnerability affecting three widely used AI-assisted code editors — Microsoft Visual Studio Code, Cursor, and Google Antigravity — was publicly disclosed on August 5, 2026. The flaw allows an attacker to embed malicious commands inside links within commit messages, and a single click by the developer triggers arbitrary code execution on their machine. Because the link appears in a trusted editor environment rather than an external channel like email, developers are less likely to scrutinize it. No CVE identifier, specific affected version numbers, or vendor-confirmed patches have been published as of the disclosure. Developers using any of the three editors are advised to treat all commit-message links with caution until official vendor advisories are released.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in