CVE-2026-26268

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/02/2026
Last modified:
18/02/2026

Description

Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection) could write to improperly protected .git settings, including git hooks, which may cause out-of-sandbox RCE next time they are triggered. No user interaction was required as Git executes these commands automatically. Fixed in version 2.5.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:anysphere:cursor:*:*:*:*:*:*:*:* 2.5 (excluding)