Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Cursor Security Bug Allowed Repositories to Execute Commands Pre Trust

August 11, 2026

Suisan City, California, Responds to Cyber Incident Amid Wave of US Lo

August 11, 2026

OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

August 11, 2026
Facebook X (Twitter) Instagram
Tuesday, August 11
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»Cursor Security Bug Allowed Repositories to Execute Commands Pre Trust
Cyber Security

Cursor Security Bug Allowed Repositories to Execute Commands Pre Trust

Team-CWDBy Team-CWDAugust 11, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A flaw in Cursor’s command-line coding agent has been found to allow a cloned repository to run any command it chose on a developer’s machine before they were asked whether they trusted it, and outside the sandbox even when the sandbox had been explicitly switched on.

Manifold Security said it reported the issue to Cursor on July 20 and published its findings on August 10. Cursor shipped a fix for the pre-trust behavior three days after the report, then closed the submission as informative, meaning no security impact, and published no advisory.

Francisco Rosales, offensive security engineer at Manifold, found the issue in the agent’s isolated worktree feature, which exists to keep an AI agent away from a developer’s working tree.

Read more on repository-triggered execution: Cursor Autorun Flaw Lets Repositories Execute Code Without Consent

Same Directory, Same Primitive

Starting the agent with the worktree flag creates a fresh checkout with no build output in it, so the agent runs a setup step by default. That step read a tracked configuration file out of the repository and passed its contents straight to a shell, with no parsing, no allowlist and no prompt.

The file arrived with an ordinary clone, so nothing about the delivery looked unusual. Manifold noted the command was unconstrained: reading SSH keys, taking cloud credentials from the environment, opening a reverse shell or writing persistence were all available.

The setup step also ran under a policy Cursor internally names for disabling the sandbox entirely, and that value is hardcoded on this path. Passing the flag to enable the sandbox did not override it.

Cursor had already patched this class once. In 2025, a repository-supplied file in the same directory auto-started an attacker’s server on open, becoming CVE-2025-64109, rated high at 8.8. The worktree feature shipped five months after that fix carrying the same primitive.

Fixed in Three Days, Then Closed as Informative

Manifold submitted the report through HackerOne with a proof-of-concept (PoC) repository and a screen recording. A new build followed on July 23 that moved the setup command behind the trust prompt.

Six days later the report was closed as informative. Manifold said Cursor gave two reasons: that exploitation requires the user to clone or open an attacker-controlled repository, and that the report did not demonstrate bypassing workspace trust.

Manifold’s response was that cloning repositories is what the product is for, and was equally a precondition of CVE-2025-64109. The two findings differ in which file carried the command, it argued, not in what the command could do.

No advisory accompanied the fix, and the build does not appear in Cursor’s July changelog. Manifold pointed out that Cursor has published advisories for this pattern twice before, and that an advisory is the channel that reaches users still running affected versions.

Developers using the worktree flag should update to build 2026.07.23-e383d2b or later, or pass the documented flag that skips worktree setup entirely. Updating closes the pre-trust window but not the sandbox gap, which Manifold said remains on current builds.

Infosecurity Magazine has approached Cursor for comment on the report’s closure and the absence of an advisory, and will update this article with any response.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleSuisan City, California, Responds to Cyber Incident Amid Wave of US Lo
Team-CWD
  • Website

Related Posts

Cyber Security

Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant

August 10, 2026
Cyber Security

Addressing Vulnerability Management Together in the Age of AI

August 7, 2026
Cyber Security

Toolkit Hidden Inside Oracle Database Evades Endpoint Tools

August 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What parents should know to protect their children from doxxing

November 28, 2025

AI-powered financial scams swamp social media

September 11, 2025

The WhatsApp screen-sharing scam you didn’t see coming

November 6, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.