UPDATE: Cursor says the malicious git.exe flaw is out of scope for its bug bounty, arguing that users choose which repositories they open.
It says the issue affects Windows only, recommends Workspace Trust, and admits it failed to respond to the researcher in time.
No fix was announced:
https://t.co/dAQkcrarKg