Skip to content
CursorGHSA-8pcm-8jpx-hv8r

Sandbox escape via Git hooks

High8.0CVE-2026-26268 · Published Feb 13, 2026 · updated Mar 16, 2026

### Impact Sandbox escape via writing `.git` configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection) could write to improperly protected `.git` settings, including git hooks, which may cause out-of-sandbox RCE next time they are triggered. No user interaction was required as Git executes these commands automatically. ### Patches Fixed in version 2.5 ### Credit Novee Security Research Team Daniel Teixeira – Nvidia AI Red Team Philip Tsukerman

GitHub advisory

Affected versions

PackageAffectedFixed in
cursor
Product
< 2.52.5
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)

More Cursor advisories

All Cursor

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.