AISLE Discovers a One-Click RCE Vulnerability in Cursor, VS Code, and Google Antigravity
Author
Stanislav Fort
Date Published
.webp%3F2026-07-31T16%3A19%3A40.215Z&w=3840&q=100)
AISLE’s AI analyzer discovered a one-click remote command execution (RCE) vulnerability in Cursor, VS Code, and Google Antigravity, which are the developer tools 50 million software engineers trust to create code. In all three of these code editors, malicious commands could be hidden within links found in commit messages. By clicking on them, you would unknowingly trigger data exfiltration, install persistent malware, or delete files.
In other words, this vulnerability allowed attackers to do whatever they wanted on your laptop. It has since been fixed across all three platforms.
From a Single Click to Total Compromise
Here’s how it worked: if you clicked on a malicious link, no pop-up warning would appear. Instead, the code editors executed arbitrary code without prompting users for confirmation. There was no way to know that the code had executed, and it gave the attacker full terminal privileges. An attacker could easily use it to:
- Exfiltrate sensitive data, such as API keys (OpenAI, Anthropic, and Stripe)
- Install persistent malware, such as keyloggers that broadcast terminal input to external servers
- Crawl the local file system or delete files
Three Platforms, One Vulnerability
When the AISLE Research Team ran automated vulnerability detection on developer tooling in fall 2025, AISLE’s analyzer agents found this critical vulnerability in VS Code. Because Cursor is built on VS Code, the issue appeared in Cursor as well. AISLE responsibly disclosed the issue to both Microsoft and Cursor as soon as our AI system flagged it. However, the issue persisted into 2026, when it made its way into Google Antigravity, Google’s AI-assisted coding environment. We immediately reported it to Google.
As soon as they received our disclosures, Google and Cursor fixed the issue. Microsoft remediated it in VS Code somewhat later, so it is no longer present on the current versions of any of these platforms. We recommend updating to the latest version to ensure you are not affected.
Getting Ahead of AI-Powered Threats with AISLE
To see what AISLE finds in your codebase, get a one-time AI code audit: Snapshot. Snapshot delivers AISLE’s industry-leading detection and triage capability in any deployment environment, including air-gapped networks, in hours. Get your Snapshot.