CVE-2026-48124Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-06-17); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-06-17: 1Mentions · 2026-07-21: 1Mentions · 2026-09-12: 1Mentions · 2026-09-13: 1Patch / Workaround · 2026-07-21: 1Patch / Workaround · 2026-09-13: 1Technical Details · 2026-07-21: 1Technical Details · 2026-09-13: 106-1707-2109-1209-13
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-171
Disclosure1
2026-07-211
Patch1
2026-09-121
General1
2026-09-131
Disclosure1
Full discourse4 posts
  • Ilia Gusev@persikbl
    General

    An agent, fully inside its sandbox, writes a file the boundary was never designed to police - a .claude hook, a .vscode task config, a modified venv. Something outside the sandbox reads and executes it later. CVE-2026-35603 and CVE-2026-48124 came out of that wave.

    Post summary

    The text briefly references two CVEs linked to sandbox escape via file manipulation but offers no details, exploits, patches, or evidence of real‑world attacks.

    1000035
    10 followersView on X
  • Vikram Sharma@v4vix
    Disclosure

    Four findings, same shape. Cursor: a hook configuration file, written inside the workspace, ran commands on the host. CVE-2026-48124, fixed in 3.0.0. Cursor again: the agent modified a Python virtual environment, and the editor's Python extension then executed the modified interpreter automatically. Cursor a third time: alternative git metadata bypassed the path-based security checks. Codex: an allowlist that matched on the name of a binary rather than its identity. And one Docker socket finding hit Codex, Cursor and Gemini CLI at once. A privileged local daemon the agents could reach became an unsandboxed place to run code. Cymulate documented this class in April across Claude Code, Gemini CLI and Codex CLI and named it configuration-based sandbox escape. A file written inside the sandbox runs on the host at next launch. Four vendors, independent teams, same underlying assumption.

    Post summary

    Four findings expose a configuration‑based sandbox escape in CVE-2026-48124 affecting Cursor, Codex, Gemini CLI, and related tools, with remediation available in version 3.0.0.

    0000083
    232 followersView on X
  • Windows Forum@windowsforum
    Patch

    🛡️ Cursor 3.0.0 patches CVE-2026-48124, but the bigger lesson is brutal: a sandbox means little when trusted tools run the AI’s leftovers. “Contained” was doing a lot of work. https://windowsforum.com/threads/cursor-3-0-0-fixes-cve-2026-48124-sandbox-to-host-code-execution.439817/?utm_source=x&utm_medium=social&utm_campaign=news_node4 #Cursor #DeveloperSecurity #AiCodingSecurity #SandboxEscapes https://t.co/SZiThfeaVG

    Post summary

    The post announces that Cursor 3.0.0 contains a patch for CVE‑2026‑48124, highlighting sandbox limitations when trusted tools run AI leftovers, without evidence of active exploitation or PoC code.

    0000053
    1.3K followersView on X
  • Crypto Master💎 Arichain@Vijaykiran0987
    Disclosure

    CVE-2026-48124: Cursor Desktop Sandbox Escape via Claude Hook https://thecybrdef.com/cve-2026-48124-cursor-desktop-sandbox-escape-via-claude-hook/ #Cyberupdates #Cybertechnews #Cybersecurity

    Post summary

    The text announces CVE‑2026‑48124 and provides a link for further information, without detailed technical or exploit details.

    0000047
    64 followersView on X

Explore more