PT-2026-47155 · Cursor · Cursor
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cursor versions prior to 3.0
Description
Cursor runs agent terminal commands in a sandbox by default. Before performing a write operation, the agent canonicalizes the target path to ensure it remains within the workspace. However, if canonicalization fails, the system falls back to the original path and executes the write without approval. A malicious agent can exploit this by creating a symlink within the workspace that points to an external location and forcing canonicalization to fail—either by ensuring the target does not exist or by removing read permissions from the path. This allows the agent to write arbitrary files outside the workspace using the user's privileges, potentially leading to non-sandboxed Remote Code Execution by overwriting the
cursorsandbox helper.Recommendations
Update to version 3.0.
Fix
RCE
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cursor