CVE-2026-26268: Cursor sandbox escape via writable .git configuration
A vulnerability in Cursor versions prior to 2.5 allowed a malicious agent, e.g. via prompt injection, to write to improperly protected .git settings including git hooks, enabling out-of-sandbox remote code execution without user interaction when Git next ran those commands. The issue was fixed in version 2.5.
Disclosed 13 February 2026 · Record updated 13 September 2026
Impact
Sandbox escape leading to code execution outside the agent sandbox on affected developer machines running Cursor versions before 2.5; no user interaction required as Git executes hook commands automatically.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-26268
