Cursor AI's Git Hook RCE Flaw: Patch Now to Secure Your Workflow
Novee Security dropped a CVSS 9.9 on Cursor. Cursor shipped 2.5. That's the rare good news in this advisory.
Most CVEs at this severity end up in the Critical, no patch yet column for weeks. CVE-2026-
otf-kit.hashnode.dev1 min read