The company quietly patched the flaw roughly seven months after receiving a private disclosure, shortly before researchers made the vulnerability public. Seven months after the vulnerability was initially disclosed, Cursor has silently patched it, just before Mindgard’s public disclosure of the issue. The vulnerability stems from how Cursor handles Git files during project initialization. However, a report from TechTimes said that Cursor quietly fixed the vulnerability on July 13. On July 14, seven months after the initial disclosure, Mindgard published the vulnerability.