A critical one-click remote code execution flaw in Microsoft VS Code, Cursor, and Google Antigravity allowed attackers to embed a malicious link in a Git commit message and trigger arbitrary code execution when a developer clicked it inside the editor. The exploit reportedly ran with the victim’s terminal privileges and required no warning or confirmation, creating a path to silent compromise across tools used by an estimated 50 million developers.
Researchers at AISLE said they first found the issue in VS Code in fall 2025 and disclosed it to Microsoft and Cursor, then identified the same inherited weakness in Google Antigravity in early 2026 because all three products shared VS Code-derived architecture. The flaw could enable credential theft, persistent malware installation, keylogging, and file access or deletion, but Google, Microsoft, and Cursor have patched the vulnerability, and current versions are reported not to contain the issue.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
AISLE later discovered the same vulnerability in Google Antigravity, which the reports describe as derived from VS Code architecture. This showed the flaw had propagated across multiple VS Code-based developer tools.
AISLE identified a critical one-click remote code execution vulnerability in Microsoft VS Code during automated vulnerability scanning. The flaw allowed arbitrary code execution when a developer clicked a malicious link embedded in a Git commit message.
Microsoft later released a fix for the VS Code vulnerability, after Google and Cursor had already remediated their affected products.
Cursor patched the inherited one-click RCE vulnerability after disclosure.
Google fixed the Google Antigravity vulnerability within days of disclosure, according to the reports.
After finding the inherited weakness in Google Antigravity, AISLE reported the issue to Google for remediation.
After identifying the vulnerability, AISLE responsibly disclosed the issue to Microsoft and Cursor. Cursor was affected because it inherited the weakness from the VS Code codebase.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.