ACVE-2026-0435
Cursor CLI 2026.07.23 on macOS, opened on an attacker-controlled workspace, ran code outside its sandbox with the logged-in user's authority without a permission prompt.
Exposure
Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
Claims on this page have not been checked against primary sources.
In the wild
demonstrated
Description
What
Accomplish demonstrated that Cursor CLI applied its macOS Seatbelt profile to model-generated shell execution but not to internal git paths. Code from an attacker-controlled workspace could therefore escape the sandbox and run with the user's authority.
Detection
Accomplish includes a proof of concept and reports the fix in Cursor CLI 2026.08.04-aaa8809.
Fix
Upgrade Cursor CLI to 2026.08.04-aaa8809 or later.
Fix
Upgrade Cursor CLI to 2026.08.04-aaa8809 or later.
- Upgrade
harness:cursor-clito2026.08.04-aaa8809. Fix independently verified by the reporter. Owner: operator