Aug 22025 Cursor AI Code Editor Fixed Flaw Allowing Attackers to Run Commands via Prompt Injection Critical flaw in Cursor AI editor let attackers execute remote code via Slack and GitHub—fixed in v1.3 update.