← Vulnerability feed

Vulnerability record · CVE-2026-26268 · published 13 February 2026

CVE-2026-26268: Anysphere cursor missing authorization vulnerability

Anysphere · Cursor

Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection) could write to improperly protected .git settings, including git hooks, which may cause out-of-sandbox RCE next time they are triggered. No user interaction was required as Git executes these commands automatically. Fixed in version 2.5.

9.9 CVSS 3.1 Critical EPSS 0.42% · top 66.0% CWE-862 · Missing authorization
9.9CVSS 3.1 base score
0.42%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection) could write to improperly protected .git settings, including git hooks, which may cause out-of-sandbox RCE next time they are triggered. No user interaction was required as Git executes these commands automatically. Fixed in version 2.5.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-26268 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-59944Anysphere cursor vulnerabilityCursor is a code editor built for programming with AI. Versions 1.6.23 and below contain case-sensitive checks in the way Cursor IDE protects its sen…EPSS 0.41%9.8CVE-2025-54130Anysphere cursor improper authorization vulnerabilityCursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions less than 1.3.9. If…EPSS 0.30%9.8CVE-2025-54135Anysphere cursor os command injection vulnerabilityCursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions below 1.3.9, If the…EPSS 1.8%9.3CVE-2026-50548Anysphere cursor path traversal vulnerabilityCursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox gra…EPSS 1.0%9.3CVE-2026-50549Anysphere cursor link following vulnerabilityCursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, the…EPSS 1.0%8.8CVE-2025-64106Anysphere cursor os command injection vulnerabilityCursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor's MCP server installation ena…EPSS 0.37%8.8CVE-2025-64107Anysphere cursor path traversal vulnerabilityCursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may lead to RCE. Cursor detects p…EPSS 0.36%8.8CVE-2025-64108Anysphere cursor path traversal vulnerabilityCursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a prompt injection attacker to ci…EPSS 0.45%

Source: NIST National Vulnerability Database (record CVE-2026-26268), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.