CVE-2026-26268
EUVD-2026-736813.02.2026, 17:16
Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection) could write to improperly protected .git settings, including git hooks, which may cause out-of-sandbox RCE next time they are triggered. No user interaction was required as Git executes these commands automatically. Fixed in version 2.5.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| anysphere | cursor | 𝑥 < 2.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration