CVE-2026-22708: Cursor has a Terminal Tool Allowlist Bypass via Environment Variables
Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, certain shell built-ins can still be executed without appearing in the allowlist and without requiring user approval. This allows an attacker via indirect or direct prompt injection to poison the shell environment by setting, modifying, or removing environment variables that influence trusted commands. This vulnerability is fixed in 2.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22708?
CVE-2026-22708 has been classified as a high severity vulnerability due to its potential to bypass security controls.
How do I fix CVE-2026-22708?
To mitigate CVE-2026-22708, upgrade the Cursor software to version 2.3 or later, where the vulnerability has been addressed.
What impact does CVE-2026-22708 have on my system?
CVE-2026-22708 allows unauthorized execution of certain shell built-ins, which could lead to potential security breaches.
In which versions of Cursor is CVE-2026-22708 present?
CVE-2026-22708 affects versions of Cursor prior to 2.3.
What is the nature of the allowlist bypass in CVE-2026-22708?
CVE-2026-22708 enables the execution of specified commands that are not included in the allowlist when the Cursor Agent is in Auto-Run Mode.