PT-2026-8013 · Cursor · Cursor

Daniel Teixeira

·

Published

2026-02-13

·

Updated

2026-05-30

·

CVE-2026-26268

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cursor versions prior to 2.5
Description A sandbox escape allows for remote code execution (RCE) when the AI agent autonomously performs Git operations. A malicious actor can hide scripts within hidden Git hooks in nested bare repositories or use prompt injection to write to improperly protected .git settings. When the AI agent executes routine commands, such as git checkout, these hooks are triggered automatically without user interaction, warnings, or prompts, leading to unauthorized code execution on the developer's machine. This issue is facilitated by the AI agent's ability to execute system-level commands and its interaction with the Cursor Rules file.
Recommendations Update to version 2.5 or higher.

Exploit

Fix

RCE

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-26268
GHSA-8PCM-8JPX-HV8R

Affected Products

Cursor