CursorGHSA-8pcm-8jpx-hv8r
Sandbox escape via Git hooks
High8.0CVE-2026-26268 · Published Feb 13, 2026 · updated Mar 16, 2026
### Impact Sandbox escape via writing `.git` configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection) could write to improperly protected `.git` settings, including git hooks, which may cause out-of-sandbox RCE next time they are triggered. No user interaction was required as Git executes these commands automatically. ### Patches Fixed in version 2.5 ### Credit Novee Security Research Team Daniel Teixeira – Nvidia AI Red Team Philip Tsukerman
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| cursor Product | < 2.5 | 2.5 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
More Cursor advisories
All Cursor| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 21 | Cursor Desktop sandbox escape via Claude hook configuration | High8.5 | 3.0.0 |
| Mar 9 | Arbitrary Code Execution via Prompt Injection and Whitelist Bypass | High | 2.0 |
| Jan 14 | Terminal Tool Allowlist Bypass via Environment Variables | High | 2.3 |
| Nov 32025 | Cursorignore Bypass via New Cursorignore Write | High | 2.0 |
| Nov 32025 | Command Injection via Untrusted MCP Configuration in Cursor CLI Beta | High8.8 | 2025.09.17-25b418f |
| Nov 32025 | Speedbump Modal Bypass in Cursor MCP Server Deep-Link | High8.8 | 2.0 |