Kinjal Das[verified]@notyourramenDisclosure
The post announces CVE-2026-22708, describes the RCE via allowlist bypass and environment manipulation, and notes that version 2.3 includes the patch, informing users to update.
Toru|AIを"あなたの業務"に落とす専門家[verified]@hz2onActive Exploitation
CVE-2026-22708 allows attackers to contaminate a cursor agent’s execution environment, bypassing command‑whitelisting and enabling arbitrary code execution in real‑world attacks.
Mohak Bajaj[verified]@MohakBajaj5Patch
The tweet announces CVE‑2026‑22708, explaining that a local file named `curl` can pass an allowlist and be executed, and it advises using absolute paths to mitigate the issue.
Levon Azevedo[verified]@BlackicelabsDisclosure
The article highlights two CVEs that share a root cause—an allowlist flaw—where one enables shell execution via crafted URLs and the other hijacks a git branch call, but does not mention patches, PoCs, or active exploitation.
Jyotirmoy Sundi[verified]@sundi133General
The statement outlines how an attacker can exploit CVE‑2026‑22708 by poisoning the agent’s environment to hijack an allowlisted command, but it provides no PoC, exploit tool, active usage evidence, or patch information.
Toru|AIを"あなたの業務"に落とす専門家[verified]@hz2onGeneral
The post explains how CVE‑2026‑22708 allows attackers to gain arbitrary code execution by contaminating the agent’s environment, highlighting that command‑name whitelists alone are insufficient.
Bradley Cassada[verified]@bcassadaDisclosure
The text announces a newly discovered allowlist bypass in Cursor allowing prompt injection that poisons the PATH, causing built‑in commands like git to execute attacker code.
jafools[verified]@crypto_foolsDisclosure
The tweet announces that CVE-2026-22708 permits remote code execution via prompt injection even when a command allowlist is empty, urging users to take five specific actions.