Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Cursor Desktop ran workspace-defined Claude hooks without user approval (CVE-2026-48124)

In Cursor Desktop versions prior to 3.0.0, workspace-defined Claude hook commands in .claude/settings.local.json could execute without dedicated user approval, letting a malicious workspace or agent-created file run local commands in the user's context at the end of an agent turn. The flaw could enable sandbox escape, persistence, local data access or further compromise, and was fixed in version 3.0.0.

Disclosed 15 June 2026 · Record updated 13 September 2026

Impact

Potential sandbox escape, persistence across agent turns, local data access or follow-on compromise on developer machines running vulnerable Cursor Desktop versions.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-48124