CVE-2026-26268Disclosure(anysphere / cursor)

CRITICALCVSS 9.9 · CRITICAL

Exploitation observed; activity peaked at 8 mentions and remains active

Immediate actions

  • Patch anysphere cursor systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection) could write to improperly protected .git settings, including git hooks, which may cause out-of-sandbox RCE next time they are triggered. No user interaction was required as Git executes these commands automatically. Fixed in version 2.5.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cursor

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 62 mentions across 30 observed days

What's happening

  • Active exploitation reported across 4 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 17 signals
  • Technical details provided in 42 signals
  • Disclosure: 26 classified signals
  • General: 17 classified signals
  • Peaked 22d ago at 8 mentions (2026-04-30); latest day: 1
  • 62 total mentions across 30 days

Affected systems

Vendors
Products
cursor

Deep dive

Activity timeline62 mentions / 30d
02468Mentions · 2026-02-13: 2Mentions · 2026-02-14: 1Mentions · 2026-02-18: 1Mentions · 2026-02-20: 1Mentions · 2026-04-19: 1Mentions · 2026-04-28: 1Mentions · 2026-04-29: 4Mentions · 2026-04-30: 8Mentions · 2026-05-01: 1Mentions · 2026-05-02: 1Mentions · 2026-05-03: 1Mentions · 2026-05-04: 7Mentions · 2026-05-05: 3Mentions · 2026-05-07: 2Mentions · 2026-05-10: 3Mentions · 2026-05-11: 3Mentions · 2026-05-12: 2Mentions · 2026-05-15: 2Mentions · 2026-05-24: 3Mentions · 2026-05-25: 1Mentions · 2026-05-30: 2Mentions · 2026-06-02: 1Mentions · 2026-06-03: 4Mentions · 2026-06-05: 1Mentions · 2026-06-12: 1Mentions · 2026-07-14: 1Mentions · 2026-07-16: 1Mentions · 2026-08-03: 1Mentions · 2026-08-10: 1Mentions · 2026-08-21: 1PoC Mentioned / Linked · 2026-04-29: 1PoC Mentioned / Linked · 2026-05-02: 1PoC Mentioned / Linked · 2026-05-05: 2PoC Mentioned / Linked · 2026-05-12: 1PoC Mentioned / Linked · 2026-06-05: 1PoC Mentioned / Linked · 2026-07-16: 1Exploit Tool / Code · 2026-05-02: 1Active Exploitation · 2026-04-30: 1Active Exploitation · 2026-05-02: 1Active Exploitation · 2026-07-14: 1Active Exploitation · 2026-08-21: 1Patch / Workaround · 2026-04-28: 1Patch / Workaround · 2026-04-30: 5Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-05-10: 2Patch / Workaround · 2026-05-11: 2Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-15: 2Patch / Workaround · 2026-05-25: 1Technical Details · 2026-02-13: 2Technical Details · 2026-02-18: 1Technical Details · 2026-02-20: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-28: 1Technical Details · 2026-04-29: 3Technical Details · 2026-04-30: 6Technical Details · 2026-05-02: 1Technical Details · 2026-05-03: 1Technical Details · 2026-05-04: 4Technical Details · 2026-05-05: 3Technical Details · 2026-05-07: 2Technical Details · 2026-05-10: 3Technical Details · 2026-05-11: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-15: 1Technical Details · 2026-05-24: 2Technical Details · 2026-05-25: 1Technical Details · 2026-05-30: 1Technical Details · 2026-06-03: 2Technical Details · 2026-07-14: 1Technical Details · 2026-07-16: 1Technical Details · 2026-08-03: 1Technical Details · 2026-08-21: 102-1302-2004-2905-0205-0505-1105-2406-0206-1208-0308-21
Signal classification6 categories
Disclosure
2641.9%
General
1727.4%
Patch
1016.1%
PoC
58.1%
Active Exploitation
34.8%
Exploit
11.6%
Referenced assets24 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-132
Disclosure1General1
2026-02-141
General1
2026-02-181
Disclosure1
2026-02-201
General1
2026-04-191
Disclosure1
2026-04-281
Disclosure1
2026-04-294
Disclosure2General1PoC1
2026-04-308
Active Exploitation1Disclosure3General1Patch3
2026-05-011
Disclosure1
2026-05-021
Active Exploitation1
2026-05-031
Disclosure1
2026-05-047
Disclosure3General3Patch1
2026-05-053
Disclosure2PoC1
2026-05-072
Disclosure1Patch1
2026-05-103
Disclosure2Patch1
2026-05-113
Disclosure1General1Patch1
2026-05-122
Disclosure1PoC1
2026-05-152
Patch2
2026-05-243
Disclosure2General1
2026-05-251
Patch1
2026-05-302
Disclosure1General1
2026-06-021
General1
2026-06-034
Disclosure1General3
2026-06-051
PoC1
2026-06-121
General1
2026-07-141
Active Exploitation1
2026-07-161
PoC1
2026-08-031
Disclosure1
2026-08-101
General1
2026-08-211
Exploit1
Full discourse20 posts
  • Keef@keef_ai
    PoC

    Clone a malicious repo with Cursor and CVE-2026-26268 turns the agent code review into arbitrary execution on your machine. The trust model is cooked. https://t.co/DgFqzOaKt8

    Post summary

    The tweet highlights a malicious repository for CVE‑2026‑26268 that demonstrates arbitrary code execution, effectively providing a proof‑of‑concept, but offers no exploitation details, active usage claims, or mitigation information.

    00060108
    1.0K followersView on X
  • Armor1@armor1_ai
    Patch

    CVE-2026-26268: Cursor RCE via hidden Git hooks. CVSS 8.1. Opening a prepared repo runs code in your session before any prompt injection or user click. Fixed in Cursor 2.5. @cursor_ai

    Post summary

    CVE-2026-26268 is a cursor RCE via hidden Git hooks with a CVSS score of 8.1, and the update has been fixed in Cursor 2.5.

    5001070
    3 followersView on X
  • Kuman@KUMAN_R
    Disclosure

    Cursorの高深刻度 CVE AI エージェントが「git checkout で hook が走る」ような当たり前の動作を、攻撃者が悪用する展開か 悪意のある攻撃者が忍ばせた、悪意のあるプリコミットフックが含まれているベアリポジトリを、Cursor エージェントが自然とHookで発火させる https://novee.security/blog/cursor-ide-cve-2026-26268-git-hook-arbitrary-code-execution/

    Post summary

    The post announces CVE‑2026‑26268, outlining how a malicious pre‑commit hook can lead to arbitrary code execution when the Cursor AI agent performs a git checkout.

    01013930
    10.9K followersView on X
  • トオル|バイブコーディング安全ガイド@hz2on
    General

    【衝撃】昨日Claude Code、今朝Cursor。Issue1つで開発機が乗っ取られる時代に突入した。CVE-2026-26268、悪意repoをエージェントに見せた瞬間アウト。守りの正解は1つしかない。↓ #バイブコーディング #セキュリティ

    Post summary

    The tweet points to CVE‑2026‑26268 and claims a malicious repo can compromise agents, but it supplies no technical specifics, defenses, or evidence of active exploitation.

    20020144
    915 followersView on X
  • 程序员潘哥@mogician301
    General

    一个哥们用 Cursor 写了半年代码,觉得效率提升巨大。今天看到 CVE-2026-26268,发现自己 clone 过的那个仓库正好触发漏洞。效率是真的提升了,别人的效率也提升了。

    Post summary

    A user notes that their cloned repository triggers CVE-2026-26268, but no technical or exploit details are provided.

    0004056
    527 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-26268 - High Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection) could write... https://www.thehackerwire.com/vulnerability/CVE-2026-26268/ https://t.co/ag0OnS8aqa

    Post summary

    The text announces CVE-2026-26268, describing a sandbox escape in Cursor's AI code editor via .git configuration writes in versions before 2.5, but does not provide a PoC, exploit tool, patch, or evidence of active exploitation.

    30100196
    112 followersView on X
  • 城咲子@jo_sekiko
    General

    AIセキュリティ記事シリーズ、全5本が揃いました。 Claude Code × MCP / Copilot × Enterprise / Cursor × CVE-2026-26268 / 4ツール権限比較—— 共通して見えてきたのは「AIが便利になるほどデフォルト権限が広がる」傾向。 信じていいのは自動化された仕組みだけです。続きはリプ欄👇

    Post summary

    The text announces a series that includes CVE-2026-26268 but provides no technical detail, proof‑of‑concept, or exploitation information, categorizing it as a general mention.

    10020159
    4.3K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The IDE That Executes First, Asks Questions Later: Cursor CVE-2026-26268 and the Agentic Coding Agent Reckoning. Cursor IDE versions <2.5 allow malicious repositories to achieve unauthenticated RCE via Git hooks—not through any flaw in Cursor's core logic, but through a…

    Post summary

    The passage discloses that Cursor IDE versions prior to 2.5 are vulnerable to an unauthenticated RCE via Git hooks (CVE-2026-26268) but does not provide a PoC, exploit, or patch information.

    2001094
    227 followersView on X
  • innovaTopia@innovaTopia_JP
    Disclosure

    Cursor 2.5未満で任意コード実行の脆弱性、何気ないGit操作が侵入口に https://innovatopia.jp/cyber-security/cyber-security-news/100370/ CVE-2026-26268 AIペネトレーションテストプラットフォームのNovee Securityによる発表。

    Post summary

    Novee Security announced CVE‑2026‑26268, a vulnerability in Cursor versions below 2.5 that allows arbitrary code execution through normal Git operations; no PoC, exploit, patch, or evidence of active exploitation is provided.

    02010150
    394 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-26268 2 - CVE-2026-27978 3 - CVE-2026-31431 4 - CVE-2026-33825 5 - CVE-2026-35414 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post only lists five trending CVEs without further technical or contextual information.

    00030187
    1.7K followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    15:19 UTC: Thread live on @lyrie_ai. This week delivered a synchronized indictment of agentic security assumptions: CVE-2026-26268 in Cursor IDE (CVSS 9.9, patched 2.5) enables a malicious Git repository to achieve RCE on a developer's machine through autonomous agent…

    Post summary

    The text announces CVE‑2026‑26268, a high‑severity RCE flaw in Cursor IDE, noting it was patched in version 2.5 and giving specific technical details, but lacks evidence of exploitation or a PoC.

    3000064
    128 followersView on X
  • 城咲子@jo_sekiko
    Disclosure

    「プロジェクトの構造を教えて」とCursorに聞いただけで攻撃者のコードが走る——CVE-2026-26268(CVSS 9.9)の仕組みを3ステップで。 ① 攻撃者がGitフックを仕込む ② 開発者がプロンプトを送る ③ AIが自律実行→フック発火 人の「注意」では防げません。続きはリプ欄👇

    Post summary

    The tweet explains the mechanism behind CVE-2026-26268, detailing how developers’ prompts can trigger an attacker’s Git hook via AI, but it offers no PoC, exploit code, patch, or evidence of active exploitation.

    10010190
    4.3K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The AI Agent That Became the Backdoor: Cursor CVE-2026-26268 Exploits Autonomous Code Review CVE-2026-26268 weaponizes Cursor's autonomous AI agent to execute arbitrary code on developer machines when cloning malicious repositories.

    Post summary

    The text announces CVE-2026-26268, noting that Cursor's autonomous AI agent can be weaponized to run arbitrary code on developer machines when cloning malicious repositories.

    2000032
    238 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE-2026-26268 The AI Agent That Became the Backdoor: Cursor CVE-2026-26268 Exploits Autonomous Code Review

    Post summary

    The headline mentions CVE-2026-26268 but provides no concrete details, tools, or evidence of exploitation, patching, or false reporting, leaving its content ambiguous.

    1001030
    238 followersView on X
  • ポメクリ@pomekuri_
    General

    @4mple_ CVE-2026-26268 とかのように、AIをそもそも使う段階で、これまでにない攻撃ルートが増えるので、個人でセキュリティレベルを上げるのは至難ですね。

    Post summary

    The post briefly mentions CVE‑2026‑26268, noting that AI adoption could introduce new attack vectors, but offers no specific technical or exploit information.

    1001069
    20 followersView on X
  • George Bevis@GeorgeBevis
    Disclosure

    🔥 TOP NEWS: → GitHub patched CVE-2026-3854 🔐 CVSS 8.7. A single git push could expose millions of private repos. Wiz: "one of the most severe SaaS vulnerabilities ever found." → Gemini CLI patched a CVSS 10.0 RCE 🚨 CI pipelines turned into supply chain attack vectors via malicious .gemini/ config in pull requests. → Cursor CVE-2026-26268 disclosed (CVSS 8.1) 💻 Sandbox escape via .git configurations. Auto-approved arbitrary code execution on opening a cloned repo. → Hugging Face and ClawHub abused for malware distribution 🦠 575 malicious skills across 13 developer accounts. Trojans, crypto miners, infostealers. https://www.bleepingcomputer.com/news/security/github-fixes-rce-flaw-that-gave-access-to-millions-of-private-repos/

    Post summary

    The post highlights recent SaaS vulnerabilities, their CVSS scores, and that GitHub, Gemini CLI, and Cursor have issued patches for CVE-2026-3854, CVE-2026-26268, and an RCE discovered with a CVSS of 10.0, respectively.

    1001096
    2.3K followersView on X
  • Aditya ✦@AdityaSeth777
    Disclosure

    CVE-2026-26268: How Cloning a Repo Can Now Execute Attacker Code in Your AI IDE https://lucidshark.com/blog/cursor-cve-2026-26268-git-hook-ai-agent-rce

    Post summary

    The passage announces CVE-2026-26268, noting that cloning a repository can trigger attacker code execution in an AI IDE via a git hook, but it does not provide any PoC, exploit code, patch, or evidence of active exploitation.

    1001050
    55 followersView on X
  • Martin Musiol@musiol_martin
    Active Exploitation

    CVE-2026-26268: clone a malicious repo, Cursor's agent silently runs arbitrary code on your laptop. The agent loop is the new RCE surface. Sandbox or get owned. Managed Claude Code lives behind your firewall. https://aigeneral.net

    Post summary

    The text announces that CVE-2026-26268 is actively exploited via Cursor’s agent, offering a malicious repository and detailing an RCE vector, with no patch or mitigation disclosed.

    10010228
    392 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    15:05 UTC: CVE-2026-26268 disclosed. The Agent Removed the Human: Prompt Injection, Git Hooks, and the Collapse of the Developer Workstation Perimeter

    Post summary

    CVE-2026-26268 was disclosed at 15:05 UTC, with the announcement titled 'The Agent Removed the Human...,' indicating a new vulnerability but providing no deeper technical or exploit details.

    2000083
    128 followersView on X
  • Ionut Popescu@NytroRST
    PoC

    Your AI Coding Agent Will Run This Exploit For You: How We Found a High-Severity CVE in Cursor https://novee.security/blog/cursor-ide-cve-2026-26268-git-hook-arbitrary-code-execution/

    Post summary

    The blog post discloses a high‑severity CVE‑2026‑26268 in Cursor IDE, presents a PoC exploiting arbitrary code execution through git hooks, but offers no patch information or evidence of active exploitation.

    00020169
    3.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appanyspherecursor---

Explore more