Cursor command-line coding agent pre-trust command execution security flaw
Vulnerability
Summary
Hide ▲
Show ▼
A Cursor vulnerability in the command-line coding agent lets a cloned repository run arbitrary commands before trust verification, creating sandbox-bypassing code-execution risk for developers. Cursor shipped a fix on July 23 after a July 20 report, but the submission was later closed as informative and no advisory was published. The flaw was found in the isolated worktree feature, and affected users should move to build 2026.07.23-e383d2b or later.
Related Happenings
HalluSquatting indirect prompt-injection attack on AI coding assistants
Technical Analysis
H score3
First: 08.07.2026 18:07
Last: 08.07.2026 18:07
Sources 1
About this happening:
Researchers demonstrated HalluSquatting, an indirect prompt-injection technique that can push AI coding assistants to fetch attacker-controlled resources and execute code....
HalluSquatting indirect prompt-injection attack on AI coding assistants
Technical AnalysisAbout this happening: Researchers demonstrated HalluSquatting, an indirect prompt-injection technique that can push AI coding assistants to fetch attacker-controlled resources and execute code....
GuardFall shell-trick bypass of command safety checks in AI coding agents
Technical Analysis
H score25
First: 30.06.2026 17:26
Last: 30.06.2026 17:26
Sources 1
About this happening:
GuardFall exposed a shell-trick bypass that lets dangerous commands slip past safety checks in open-source AI coding and computer-use agents, putting full account access...
GuardFall shell-trick bypass of command safety checks in AI coding agents
Technical AnalysisAbout this happening: GuardFall exposed a shell-trick bypass that lets dangerous commands slip past safety checks in open-source AI coding and computer-use agents, putting full account access...
Cursor IDE MCP deeplink code execution security flaw
Vulnerability
H score37
First: 17.03.2026 17:00
Last: 17.03.2026 17:00
Sources 1
About this happening:
A Cursor IDE flaw in MCP deeplinks can let crafted installation links trigger arbitrary commands or install malicious components under some user-approval and confi...
Cursor IDE MCP deeplink code execution security flaw
VulnerabilityAbout this happening: A Cursor IDE flaw in MCP deeplinks can let crafted installation links trigger arbitrary commands or install malicious components under some user-approval and confi...
Timeline
-
11.08.2026 17:30 2 articles · 4h ago
Manifold reports pre-trust command execution in Cursor's coding agent
Initial DisclosureManifold Security reported to Cursor on July 20, 2026 that a cloned repository could make Cursor's command-line coding agent run arbitrary commands on a developer's machine before trust verification and outside the sandbox even when sandboxing was enabled. The submission included a proof-of-concept repository and a screen recording, and the finding centered on the isolated worktree feature that is meant to keep the agent away from a developer's working tree.
Show sources
- Cursor Security Bug Allowed Repositories to Execute Commands Before Trust Verification — www.infosecurity-magazine.com — 11.08.2026 17:30
- Cursor Security Bug Allowed Repositories to Execute Commands Before Trust Verification — www.infosecurity-magazine.com — 11.08.2026 17:30
-
11.08.2026 17:30 1 articles · 4h ago
Cursor moves worktree setup behind the trust prompt
Mitigation Patch UpdateCursor shipped a new build on July 23, 2026 that moved the setup command behind the trust prompt, closing the pre-trust execution path in the worktree flow. The change addressed the repository-triggered command execution that had been reachable before the user approved the checkout.
Show sources
- Cursor Security Bug Allowed Repositories to Execute Commands Before Trust Verification — www.infosecurity-magazine.com — 11.08.2026 17:30
-
11.08.2026 17:30 1 articles · 4h ago
Cursor closes the submission as informative without an advisory
Legal Policy Action UpdateSix days after the July 20, 2026 report, Cursor closed the submission as informative, saying exploitation would require a user to clone or open an attacker-controlled repository and that the report did not demonstrate a workspace trust bypass. Cursor also published no advisory for the fix, leaving affected users without a notice channel for older builds.
Show sources
- Cursor Security Bug Allowed Repositories to Execute Commands Before Trust Verification — www.infosecurity-magazine.com — 11.08.2026 17:30