Cursor Security Bug: Repos Execute Commands Pre-Trust

Aug 11·0:00 listen·Source: Infosecurity Magazine

Summary

A security flaw in Cursor's command-line coding agent allowed cloned repositories to execute commands on a developer's machine without prior trust or sandbox protection. Manifold Security reported this issue to Cursor on July 20. Cursor then shipped a fix for the pre-trust behavior three days later. However, Cursor closed the submission as "informative," stating it had no security impact, and did not publish an advisory. The vulnerability was found in the agent's isolated worktree feature. This feature runs a setup step that reads a configuration file from the repository and passes its contents directly to a shell, without parsing or a prompt. This allowed unconstrained commands to run, even when the sandbox was explicitly enabled. Manifold Security noted that cloning repositories is a core function of the product, making the vulnerability significant. This issue is similar to a previous vulnerability, CVE-2025-64109, which was rated high. Developers using the worktree flag should update to build 2026.07.23-e383d2b or later, or use the flag to skip worktree setup. This is important to protect against potential security risks from malicious repositories.

Read the full article on Infosecurity Magazine

This is an AI-generated audio summary. Always check the original source for complete reporting.

Share
Keep Listening