A critical one-click remote code execution (RCE) flaw has been identified across three of the world's most popular coding tools: Cursor, Microsoft Visual Studio Code, and Google Antigravity This article explores uncovering 225 vulnerabilities. . The vulnerability was discovered by AI-native security firm AISLE, exposing an estimated 50 million software developers to silent system compromise via a single click on a malicious link.
Attackers could embed a malicious link in a Git commit message, triggering arbitrary code execution with full terminal privileges without prompting or confirmation. This vulnerability allowed attackers to steal sensitive credentials like OpenAI, Anthropic, and Stripe API keys, install persistent malware that broadcasts terminal input to external servers, and manipulate local file systems or delete files at will.
Because the exploit could operate without user awareness, security teams should also review recent commit history for suspicious or unfamiliar links and rotate any API keys or credentials that may have been exposed during affected editor versions' use. AISLE, designated as a CVE Numbering Authority, has credited its AI-driven analyzer agents with uncovering over 225 vulnerabilities in dozens of widely used open-source projects, including OpenSSL, curl, and FreeBSD. Detect, investigate, and respond faster using ANY.RUN's in-browser data inspection capabilities to strengthen your SOC and reduce Mean Time To Repair (MTTR).












