CVE-2026-22708: Cursor agent allowlist bypass lets shell built-ins run unapproved
In Cursor versions prior to 2.3, the AI coding agent running in Auto-Run Mode with Allowlist mode enabled could execute certain shell built-ins without appearing in the allowlist or requiring user approval, letting an attacker use direct or indirect prompt injection to poison the shell environment by altering environment variables that influence trusted commands. The issue is fixed in version 2.3.
Disclosed 14 January 2026 · Record updated 13 September 2026
Impact
Attackers could bypass the agent's command allowlist and approval prompts to set, modify or remove environment variables, influencing the behaviour of trusted commands run by the agent.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-22708
