PT-2026-49469 · Cursor · Cursor
CVE-2026-48124
·
Published
2026-06-15
·
Updated
2026-06-16
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Cursor versions prior to 3.0.0
Description
Cursor Desktop allows the execution of workspace-defined Claude hook commands located in
.claude/settings.local.json without requiring explicit user approval. A malicious workspace or a file created by an agent could configure these hooks to run local commands within the user's context upon the completion of an agent turn. This behavior could lead to sandbox escape, persistence across turns, unauthorized local data access, or further system compromise.Recommendations
Update to version 3.0.0.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cursor