Skip to content
CursorGHSA-pc9j-3qc2-95wv

Cursor Desktop sandbox escape via Claude hook configuration

High8.5CVE-2026-48124 · Published May 21, 2026

### Summary Cursor Desktop could execute workspace-defined Claude hook commands from `.claude/settings.local.json` without dedicated user approval. ### Impact A malicious workspace or agent-created file could configure hooks that run local commands in the user's context when an agent turn ends. This could allow sandbox escape, persistence across turns, local data access, or follow-on compromise. ### Remediation Update Cursor Desktop to a patched version. Workspace-sourced hook commands now require appropriate approval and are subject to the same execution policy controls as other agent shell commands.

GitHub advisory

Affected versions

PackageAffectedFixed in
Cursor
Product
< 3.0.03.0.0
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)

More Cursor advisories

All Cursor

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.