A critical one-click remote code execution (RCE) vulnerability affects three of the world's most widely used code editors: Cursor, Microsoft Visual Studio Code, and Google Antigravity This article explores malicious link developer. . The flaw, discovered by AISLE, exposes an estimated 50 million software developers at risk of silent, total system compromise with just a single click on a malicious link.
When a developer clicks that link inside the editor, it executes arbitrary code with full terminal privileges without displaying any confirmation dialog, warning prompt, or visible indication of what happened. Victims lacked real-time detection capabilities, allowing attackers to gain complete control over their machines without being noticed.
Malware could also install persistent threats including keyloggers that broadcast keystrokes to an external server and freely crawl or delete files across the local file system. This case highlights a growing trend in the AI coding tool ecosystem: because many AI-native IDEs are forked from a common codebase like VS Code, a single vulnerability can silently spread across multiple products used by tens of millions of developers before it is caught. Developers using any of these three editors must upgrade to the latest available versions immediately to safeguard against this critical vulnerability, which operates without user awareness and requires teams to review recent commit histories and rotate API keys or credentials in projects affected by those editor versions.












