frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Cursor runs shell commands straight from files

https://twitter.com/pelaseyed/status/1958857885670162801
1•homanp•2h ago

Comments

homanp•2h ago
I was experimenting with different injection techniques for a model dataset and came across something… concerning.

If a file contains instructions like “run this shell command,” Cursor doesn’t stop to ask or warn you. It just… runs it. Directly on your local machine.

That means if you:

1) Open a malicious repo 2) Ask to summarize or inspect a file

…Cursor could end up executing arbitrary commands — including things like exfiltrating environment variables or installing malware.

To be clear:

- I’ve already disclosed this responsibly to the Cursor team. - I’m redacting the actual payload for safety. - The core issue: the “human-in-the-loop” safeguard is skipped when commands come from files.

This was a pretty simple injection, nothing facing. Is Cursor outsourcing security to the models or do they deploy strategies to identify/intercept this kind of thing?

Feels like each new feature release could be a potential new attack vector.

Show HN: Prisma-Prefixed-IDs – Stripe-Like Prefixes for Prisma JavaScript

https://github.com/pureartisan/prisma-prefixed-ids
1•prageeths•50s ago•0 comments

Deep Learning Tuning Playbook

https://github.com/google-research/tuning_playbook
1•sonabinu•1m ago•0 comments

SQLite-Vector adds support for float16 and bfloat16 (CPU, NEON, AVX2 and SSE2)

https://github.com/sqliteai/sqlite-vector
1•marcobambini•1m ago•0 comments

PHP: A fractal of bad design (2012)

https://eev.ee/blog/2012/04/09/php-a-fractal-of-bad-design/
1•utf_8x•1m ago•0 comments

Show HN: Goo is go plus oh my features

https://github.com/pannous/goo
1•singularity2001•1m ago•0 comments

Building software on top of an LLM is hard, but not that hard

https://reedtaylorbarnes.com/blog/building-with-llms/
1•ketzo•2m ago•0 comments

Janito 2.33.0

1•joaompinto•2m ago•0 comments

Britain's Pub Culture Faces a Mortal Threat: The Single-File Queue

https://www.wsj.com/world/britains-pub-culture-faces-a-mortal-threat-the-single-file-queue-0b6688af
1•impish9208•2m ago•1 comments

So you want to move some data from A to B in AWS

https://simonam.dev/aws-s3-to-efs/
1•furkansahin•4m ago•0 comments

Improving Our Nation Through Better Design

https://www.whitehouse.gov/presidential-actions/2025/08/improving-our-nation-through-better-design/
1•keepamovin•4m ago•0 comments

Flying the Apollo 11 Moon Landing with the Original AGC Code [video]

https://www.youtube.com/watch?v=r_eBGSe5zEQ
1•mariuz•4m ago•0 comments

Speculation around 3I/ATLAS, an interstellar traveler approaching this December

https://www.clickworlddaily.com/2025/08/the-silent-shape-approaching-december.html
1•jonalgarve•5m ago•0 comments

Sshuttle: Where transparent proxy meets VPN meets SSH

https://github.com/sshuttle/sshuttle
1•warrenm•8m ago•0 comments

You Feel Like Shit

https://philome.la/jace_harr/you-feel-like-shit-an-interactive-self-care-guide/play/index.html
1•surprisetalk•8m ago•0 comments

I guess I was wrong about AI persuasion

https://dynomight.net/persuasion/
1•surprisetalk•8m ago•0 comments

Why is choral music harder to appreciate?

https://marginalrevolution.com/marginalrevolution/2025/08/why-is-choral-music-harder-to-appreciate.html
1•surprisetalk•8m ago•0 comments

ShipGoo001

https://en.wikipedia.org/wiki/ShipGoo001
1•surprisetalk•8m ago•0 comments

Nvidia Urges Taiwan to Embrace Nuclear Power Ahead of Referendum

https://www.bloomberg.com/news/articles/2025-08-22/nvidia-urges-taiwan-to-embrace-nuclear-power-ahead-of-referendum
2•keepamovin•9m ago•0 comments

MoQ: Refactoring the Internet's real-time media stack

https://blog.cloudflare.com/moq/
2•englishm•12m ago•0 comments

Georgism

https://en.wikipedia.org/wiki/Georgism
3•tomrod•13m ago•0 comments

I quit my job to build my own startup

https://www.paritydeals.com/blog/i-quit-my-job-to-build-my-own-startup/
2•geojacobm6•14m ago•0 comments

Ancient bones suggest humans interbred with Neanderthals 100k years earlier

https://apnews.com/article/israel-archaeology-neanderthals-sapiens-evolution-773d0cf2e142871cdbb047dc72e7417b
1•gmays•17m ago•0 comments

FBI searches home and office of ex-Trump national security adviser John Bolton

https://apnews.com/article/trump-fbi-bolton-patel-records-home-search-d02cca9e51360115262727ce45be3d65
3•throw0101a•17m ago•0 comments

Show HN: Implement BLAKE3 with Awk

https://github.com/chirsz-ever/awk-hashsum
1•chirsz•20m ago•0 comments

American Citizens Abroad

https://www.americansabroad.org/
2•Propelloni•20m ago•1 comments

Show HN: AIMless – a 10 KB single file P2P chat app with zero dependencies

https://github.com/ImZackAdams/AIMless
1•NyxBNC•22m ago•0 comments

Data Integrity: The Key to Trust in AI Systems

https://spectrum.ieee.org/data-integrity
3•walterbell•22m ago•0 comments

Write Badly

https://kupajo.com/write-badly
1•kolyder•24m ago•0 comments

Ostrich Algorithm

https://en.wikipedia.org/wiki/Ostrich_algorithm
2•lucaspauker•25m ago•1 comments

Discourse 3.5

https://blog.discourse.org/2025/08/unboxing-discourse-3-5/
1•pentagrama•25m ago•0 comments