Tag
A zero-day vulnerability in Cursor IDE allows arbitrary code execution via a malicious git.exe in the project root with no user interaction. Mindgard disclosed it seven months ago, but Cursor has not patched it.
A vulnerability in KDE Plasma allows sandboxed applications (e.g., Flatpak) to escape and execute arbitrary code on the host via the 'Open New Window' action, impersonating other applications. A proof of concept is provided.