Find notable cyber news and cases, enriched with sources, timelines, and signals.

Cursor command-line coding agent pre-trust command execution security flaw

Vulnerability
First reported
Last updated
Happening score
H score 26
1 unique sources, 1 articles

Summary

Hide ▲

A Cursor vulnerability in the command-line coding agent lets a cloned repository run arbitrary commands before trust verification, creating sandbox-bypassing code-execution risk for developers. Cursor shipped a fix on July 23 after a July 20 report, but the submission was later closed as informative and no advisory was published. The flaw was found in the isolated worktree feature, and affected users should move to build 2026.07.23-e383d2b or later.

Related Happenings

HalluSquatting indirect prompt-injection attack on AI coding assistants

Technical Analysis
H score3 First: 08.07.2026 18:07 Last: 08.07.2026 18:07 Sources 1

About this happening: Researchers demonstrated HalluSquatting, an indirect prompt-injection technique that can push AI coding assistants to fetch attacker-controlled resources and execute code....

GuardFall shell-trick bypass of command safety checks in AI coding agents

Technical Analysis
H score25 First: 30.06.2026 17:26 Last: 30.06.2026 17:26 Sources 1

About this happening: GuardFall exposed a shell-trick bypass that lets dangerous commands slip past safety checks in open-source AI coding and computer-use agents, putting full account access...

Cursor IDE MCP deeplink code execution security flaw

Vulnerability
H score37 First: 17.03.2026 17:00 Last: 17.03.2026 17:00 Sources 1

About this happening: A Cursor IDE flaw in MCP deeplinks can let crafted installation links trigger arbitrary commands or install malicious components under some user-approval and confi...

Timeline

  1. 11.08.2026 17:30 2 articles · 4h ago

    Manifold reports pre-trust command execution in Cursor's coding agent

    Initial Disclosure

    Manifold Security reported to Cursor on July 20, 2026 that a cloned repository could make Cursor's command-line coding agent run arbitrary commands on a developer's machine before trust verification and outside the sandbox even when sandboxing was enabled. The submission included a proof-of-concept repository and a screen recording, and the finding centered on the isolated worktree feature that is meant to keep the agent away from a developer's working tree.

    Show sources
  2. 11.08.2026 17:30 1 articles · 4h ago

    Cursor moves worktree setup behind the trust prompt

    Mitigation Patch Update

    Cursor shipped a new build on July 23, 2026 that moved the setup command behind the trust prompt, closing the pre-trust execution path in the worktree flow. The change addressed the repository-triggered command execution that had been reachable before the user approved the checkout.

    Show sources
  3. 11.08.2026 17:30 1 articles · 4h ago

    Cursor closes the submission as informative without an advisory

    Legal Policy Action Update

    Six days after the July 20, 2026 report, Cursor closed the submission as informative, saying exploitation would require a user to clone or open an attacker-controlled repository and that the report did not demonstrate a workspace trust bypass. Cursor also published no advisory for the fix, leaving affected users without a notice channel for older builds.

    Show sources