Junglewise Threat Intelligence

CVE-2026-50548: Cursor AI Editor sandbox escape via agent-controlled working directory

CVE-2026-50548 · Severity: info · CVSS 9.3 · Published 2026-06-25

Technologies: Anysphere (Cursor) Cursor. Vendors: Anysphere.

Executive brief

Cursor is an AI-powered code editor used by developers to write and manage software. A security flaw allowed the AI agent to bypass its safety sandbox and write files to sensitive locations on the user's computer. This could allow a malicious agent to take full control of the user's system and execute unauthorized commands without any interaction from the user beyond a standard prompt.

Technical details

A path traversal vulnerability (CWE-22) exists in Cursor versions prior to 3.0. The application's AI agent runs terminal commands within a sandbox that automatically grants write access to the command's working directory. However, the agent could manipulate the 'working_directory' parameter to point to sensitive locations outside the intended workspace. An attacker could exploit this to overwrite critical system or application files, such as the 'cursorsandbox' helper, leading to full escape from the sandbox and non-sandboxed Remote Code Execution (RCE) under the privileges of the local user. This issue is resolved in version 3.0 by removing write access based on agent-controlled directory parameters.

Affected products

  • Anysphere (Cursor) Cursor < 3.0

Timeline

  • 2026-06-05: advisory: GitHub advisory published by vendor
  • 2026-06-25: disclosed: CVE published to NVD

References

Related threats