CVE-2026-48124: Cursor Desktop sandbox escape via Claude hook configuration
Cursor is a code editor built for programming with AI. In versions prior to 3.0.0, the Cursor Desktop could execute workspace-defined Claude hook commands from .claude/settings.local.json without dedicated user approval. A malicious workspace or agent-created file could configure hooks that run local commands in the user's context when an agent turn ends. This could allow sandbox escape, persistence across turns, local data access, or follow-on compromise. This issue has been fixed in version 3.0.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cursor Desktopto a version that resolves this vulnerability.Fixed in 3.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48124?
CVE-2026-48124 has a high severity rating of 8.5.
How do I fix CVE-2026-48124?
To fix CVE-2026-48124, update to Cursor Desktop version 3.0.0 or later.
What does CVE-2026-48124 exploit?
CVE-2026-48124 exploits a sandbox escape vulnerability via unapproved Claude hook commands in Cursor Desktop.
Which versions of Cursor Desktop are affected by CVE-2026-48124?
CVE-2026-48124 affects Cursor Desktop versions prior to 3.0.0.
What type of vulnerability is CVE-2026-48124 classified as?
CVE-2026-48124 is classified as a code injection vulnerability.