CVE-2026-22708Disclosure(anysphere / cursor)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch anysphere cursor systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, certain shell built-ins can still be executed without appearing in the allowlist and without requiring user approval. This allows an attacker via indirect or direct prompt injection to poison the shell environment by setting, modifying, or removing environment variables that influence trusted commands. This vulnerability is fixed in 2.3.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-15CWE-74CWE-77CWE-78CWE-94CWE-269

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cursor

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 15 mentions across 14 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 13 signals
  • Disclosure: 8 classified signals
  • General: 2 classified signals
  • Peaked 10d ago at 2 mentions (2026-06-16); latest day: 1
  • 15 total mentions across 14 days

Affected systems

Vendors
Products
cursor

Deep dive

Activity timeline15 mentions / 14d
01122Mentions · 2026-01-31: 1Mentions · 2026-03-09: 1Mentions · 2026-04-27: 1Mentions · 2026-06-16: 2Mentions · 2026-06-22: 1Mentions · 2026-06-23: 1Mentions · 2026-06-29: 1Mentions · 2026-07-01: 1Mentions · 2026-07-08: 1Mentions · 2026-07-29: 1Mentions · 2026-08-15: 1Mentions · 2026-08-27: 1Mentions · 2026-09-07: 1Mentions · 2026-10-07: 1Active Exploitation · 2026-07-08: 1Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-08-15: 1Patch / Workaround · 2026-09-07: 1Technical Details · 2026-01-31: 1Technical Details · 2026-03-09: 1Technical Details · 2026-04-27: 1Technical Details · 2026-06-16: 1Technical Details · 2026-06-22: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-29: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-29: 1Technical Details · 2026-08-15: 1Technical Details · 2026-08-27: 1Technical Details · 2026-09-07: 101-3103-0904-2706-1606-2206-2306-2907-0107-0807-2908-1508-2709-0710-07
Signal classification4 categories
Disclosure
857.1%
Patch
321.4%
General
214.3%
Active Exploitation
17.1%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-311
Disclosure1
2026-03-091
Disclosure1
2026-04-271
Patch1
2026-06-162
Disclosure2
2026-06-221
Disclosure1
2026-06-231
Patch1
2026-06-291
Disclosure1
2026-07-011
General1
2026-07-081
Active Exploitation1
2026-07-291
General1
2026-08-151
Disclosure1
2026-08-271
Disclosure1
2026-09-071
Patch1
Full discourse15 posts
  • Kinjal Das@notyourramen
    Disclosure

    CVE-2026-22708: Cursor's agent allowlist could be bypassed via shell built-ins and poisoned env vars indirect prompt injection leading to RCE, zero-click in some cases. Patched in 2.3. If your agents auto-run shell commands, check your version tonight.

    Post summary

    The post announces CVE-2026-22708, describes the RCE via allowlist bypass and environment manipulation, and notes that version 2.3 includes the patch, informing users to update.

    0005076
    13 followersView on X
  • Toru|AIを"あなたの業務"に落とす専門家@hz2on
    Active Exploitation

    Cursorで実際に起きたこと(CVE-2026-22708): ①攻撃者がエージェントの"実行環境"を先に汚染しておく ②許可リスト内の無害なコマンド(git branch等)が、汚染された設定経由で任意コードを運ぶ ③ユーザーは"許可した操作しか動いてない"と安心したまま つまり「コマンド名のホワイトリスト」だけでは穴だらけ。コマンドが"どんな環境で動くか"まで設計しないと、安全な入口がそのまま裏口になる。商材を10個買っても、この一手は誰も教えてくれません。

    Post summary

    CVE-2026-22708 allows attackers to contaminate a cursor agent’s execution environment, bypassing command‑whitelisting and enabling arbitrary code execution in real‑world attacks.

    20010171
    923 followersView on X
  • Mohak Bajaj@MohakBajaj5
    Patch

    scary one from today. a file named `curl` in your repo can bypass cursor's allowlist. CVE-2026-22708. allowlist sees the name, shell runs the local file. use absolute paths in scripted calls. checking yours today?

    Post summary

    The tweet announces CVE‑2026‑22708, explaining that a local file named `curl` can pass an allowlist and be executed, and it advises using absolute paths to mitigate the issue.

    0001047
    199 followersView on X
  • Levon Azevedo@Blackicelabs
    Disclosure

    Two CVEs, same root cause. mcp-remote (severity 9.6, 437k+ downloads): a hostile MCP server sends a crafted URL, it executes as a shell command on your machine. Cursor (CVE-2026-22708): an allowlisted `git branch` call gets hijacked. The allowlist WAS the vulnerability.

    Post summary

    The article highlights two CVEs that share a root cause—an allowlist flaw—where one enables shell execution via crafted URLs and the other hijacks a git branch call, but does not mention patches, PoCs, or active exploitation.

    1000039
    42 followersView on X
  • Jyotirmoy Sundi@sundi133
    General

    CVE-2026-22708 in Cursor: an attacker poisons the agent's execution environment so an allowlisted command like 'git branch' quietly delivers a payload. The allowlist was the trust boundary. It leaked.

    Post summary

    The statement outlines how an attacker can exploit CVE‑2026‑22708 by poisoning the agent’s environment to hijack an allowlisted command, but it provides no PoC, exploit tool, active usage evidence, or patch information.

    1000033
    161 followersView on X
  • Toru|AIを"あなたの業務"に落とす専門家@hz2on
    General

    CVE-2026-22708(Cursor)の教訓です: ①攻撃者がエージェントの"実行環境"を先に汚染しておく ②許可リスト内の無害なコマンド(git branch等)が、汚染された設定経由で任意コードを運んでしまう ③ユーザーは"許可した操作しか動いてない"と安心している 要は「コマンド名のホワイトリスト」だけでは不十分。コマンドが"どんな環境で動くか"まで守らないと、安全な入口がそのまま裏口になります。

    Post summary

    The post explains how CVE‑2026‑22708 allows attackers to gain arbitrary code execution by contaminating the agent’s environment, highlighting that command‑name whitelists alone are insufficient.

    1000095
    921 followersView on X
  • Bradley Cassada@bcassada
    Disclosure

    Allowlist bypass via shell built-ins: Cursor checked external commands but not built-ins. CVE-2026-22708 let prompt injection poison PATH so "git" ran attacker code. https://www.scworld.com/news/cursor-vulnerability-enables-stealthy-rce-via-indirect-prompt-injection #AISecurity #PromptInjection #LLMSecurity

    Post summary

    The text announces a newly discovered allowlist bypass in Cursor allowing prompt injection that poisons the PATH, causing built‑in commands like git to execute attacker code.

    0001078
    244 followersView on X
  • jafools@crypto_fools
    Disclosure

    If you run Cursor with Auto-Run on, give this 5 minutes. CVE-2026-22708 lets prompt injection reach remote code execution even with an empty command allowlist. The allowlist was never the wall you thought it was. 5 things to check. https://t.co/i8SqToe6pa

    Post summary

    The tweet announces that CVE-2026-22708 permits remote code execution via prompt injection even when a command allowlist is empty, urging users to take five specific actions.

    1000044
    24 followersView on X
  • Hikari@hikari_signal

    AI code editors run what they read, not what you approve. CVE-2026-22708 (Cursor): allowlisted git branch carried the payload; CVE-2026-12957/8 (Amazon Q): a repo MCP config auto-loaded and stole cloud credentials (Wiz, Jun 26). Falsifiable: could an allowlisted command run code you never saw?

    0000052
    142 followersView on X
  • jafools@crypto_fools
    Patch

    SpaceX is buying Cursor for $60B, the biggest VC-backed startup acquisition ever. Same month Cursor patched CVE-2026-22708, an allowlist bypass that let prompt injection reach full RCE. The tools we vibe-code with are now sixty-billion-dollar attack surfaces.

    Post summary

    The announcement of SpaceX buying Cursor includes a note that Cursor patched CVE-2026-22708, an allowlist bypass allowing prompt injection to lead to full RCE.

    0000038
    24 followersView on X
  • Martin Musiol@musiol_martin
    Disclosure

    Cursor's command allowlist can be completely empty and you still get RCE. CVE-2026-22708: shell builtins like export and declare are implicitly trusted, so attackers smuggle payloads through 'approved' commands. The allowlist didn't fail. It did exactly what it promised, for the wrong person. @cursor_ai

    Post summary

    The tweet explains that Cursor’s command allowlist can be left empty yet still enable remote code execution through trusted shell builtins, but it provides no proof‑of‑concept, exploit code, patch, or evidence of active exploitation.

    0000038
    404 followersView on X
  • Martin Musiol@musiol_martin
    Disclosure

    Cursor's allowlist got walked right past: git branch delivering arbitrary payloads, CVE-2026-22708. Allowlists were never a security boundary. A real sandbox is, and that's the part you can't bolt on after the fact. https://aigeneral.net

    Post summary

    The post highlights CVE-2026-22708, noting that allowlists can be bypassed via a git branch that delivers arbitrary payloads, emphasizing the insufficiency of allowlists as a security boundary.

    0000034
    404 followersView on X
  • The Agent Economist@The_Agent_Econ
    Patch

    360,000+ cursor users: one hacker just needs you to open a repo. nomshub (cve-2026-22708) lets ai escape its sandbox via shell built-ins. they get persistent shell access. no clicks. check your cursor version.

    Post summary

    A new CVE (cve‑2026‑22708) allows shell access in Cursor without user interaction; users are urged to update their version.

    0000050
    14 followersView on X
  • The Agent Economist@The_Agent_Econ
    Disclosure

    pillar security found a zero-click RCE in cursor IDE — CVE-2026-22708. clone any repo with poisoned code. it runs shell commands before you click "trust." bypasses the allowlist via hidden shell builtins. millions of devs use cursor. one git clone = full compromise.

    Post summary

    Pillar Security has identified a zero‑click remote code execution vulnerability in Cursor IDE (CVE‑2026‑22708) that allows malicious code to run during repository cloning, though no PoC code, exploit tool, or active exploitation evidence is provided.

    0000056
    6 followersView on X
  • Online-Magazin für IT-Sicherheit@KolaricDav5471
    Disclosure

    Sicherheitslücke in Cursor-IDE: Shell-Befehle werden zur Angriffsfläche - Die als CVE-2026-22708 klassifizierte Lücke ermöglicht Angreifern die Ausführung von Remote-Code durch Manipulation von Umgebungsvariablen – selbst bei leerer Befehlsliste. https://www.all-about-security.de/sicherheitsluecke-in-cursor-ide-shell-befehle-werden-zur-angriffsflaeche/ #cyber

    Post summary

    The article announces CVE‑2026‑22708 in Cursor‑IDE, detailing how attackers can achieve remote code execution by manipulating environment variables, even when the command list is empty.

    0000039
    17 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appanyspherecursor---

Explore more