Executive brief
Cursor, an AI-powered code editor, contains a vulnerability that allows its AI agent to bypass security restrictions and write files anywhere on a user's computer. By tricking the software's safety checks using symbolic links, a malicious agent can escape its restricted environment (sandbox) to modify system files or install malicious software. This could lead to full control over the user's machine with no interaction required beyond a standard AI prompt.
Technical details
A sandbox escape exists in Cursor versions prior to 3.0 due to improper path canonicalization (CWE-59). When the AI agent attempts a file write, it tries to canonicalize the path to ensure it remains within the workspace; however, if canonicalization fails (e.g., due to a non-existent target or restricted read permissions), the system incorrectly falls back to the original path and proceeds with the write without user approval. An attacker can exploit this by creating a symlink within the workspace that points to a sensitive location outside the workspace. By forcing a canonicalization failure, the agent can write through the symlink to arbitrary locations, potentially overwriting the 'cursorsandbox' helper to achieve non-sandboxed Remote Code Execution (RCE). This issue is resolved in version 3.0 by blocking writes when canonicalization fails.
Affected products
- Cursor Cursor < 3.0
Timeline
- 2026-06-05: advisory: GitHub advisory published
- 2026-06-25: disclosed: CVE published to NVD