Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-50548: Cursor AI Editor: Unrestricted File Access

CVE-2026-50548
Summary

Prior to Cursor version 3.0, a security flaw allowed a malicious AI agent to write files outside the intended workspace. This could lead to unauthorized code execution. Users should update to Cursor version 3.0 or later to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
anysphere cursor < 3.0
cpe:2.3:a:anysphere:cursor:*:*:*:*:*:*:*:*
Original title
Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox grants write access to the command's working direct...
Original description
Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox grants write access to the command's working directory. A flaw was identified in how the agent could modify the working_directory parameter, which could cause the sandbox to include writable paths outside the intended workspace. A malicious agent could set working_directory to a sensitive location and write arbitrary files outside the workspace under the user's privileges. This enables non-sandboxed Remote Code Execution — for example by overwriting the cursorsandbox helper so later commands run unsandboxed — with no user interaction beyond a benign prompt. This vulnerability is fixed in 3.0.
nvd CVSS4.0 9.3
Vulnerability type
CWE-22 Path Traversal
Published: 25 Jun 2026 · Updated: 23 Jul 2026 · First seen: 25 Jun 2026