Skip to content
CursorGHSA-3p48-7v9f-v5cw

Cursor Desktop sandbox escape via agent-controlled working directory

CriticalCVE-2026-50548 · Published Jun 5, 2026

### Summary Cursor runs agent terminal commands in a sandbox by default, and the sandbox grants write access to the command's working directory. A flaw was identified in how the agent could modify the `working_directory` parameter, which could cause the sandbox to include writable paths outside the intended workspace. ### Impact A malicious agent could set `working_directory` to a sensitive location and write arbitrary files outside the workspace under the user's privileges. This enables non-sandboxed Remote Code Execution — for example by overwriting the `cursorsandbox` helper so later commands run unsandboxed — with no user interaction beyond a benign prompt. ### Remediation Update Cursor to version 3.0. The sandbox no longer grants write access based on an agent-controlled working directory. ### Credit Cato AI Labs

GitHub advisory

Affected versions

PackageAffectedFixed in
Cursor
Product
< 3.03.0
Details and references

More Cursor advisories

All Cursor

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.