CVE-2026-26268
HIGHCursor < 2.5 - Sandbox Escape and Remote Code Execution via .git Configuration Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2026-26268. PoCs published by dhawaldesai.
AI-analyzed exploit summary This repository provides a detection scanner for multiple AI coding assistant vulnerabilities, including CVE-2026-26268 (Cursor). It includes a bash script (`ais.sh`) that performs 11 checks for indicators of compromise (IOCs) related to Mini Shai-Hulud, Gemini CLI RCE, and Cursor CVE-2026-26268. The scanner is designed to detect malicious configurations, hooks, and dependencies but does not include exploit code.
Description
Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection) could write to improperly protected .git settings, including git hooks, which may cause out-of-sandbox RCE next time they are triggered. No user interaction was required as Git executes these commands automatically. Fixed in version 2.5.
Exploits (1)
This repository provides a detection scanner for multiple AI coding assistant vulnerabilities, including CVE-2026-26268 (Cursor). It includes a bash script (`ais.sh`) that performs 11 checks for indicators of compromise (IOCs) related to Mini Shai-Hulud, Gemini CLI RCE, and Cursor CVE-2026-26268. The scanner is designed to detect malicious configurations, hooks, and dependencies but does not include exploit code.
References (1)
Scores
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H