CVE-2026-26268

HIGH

Cursor < 2.5 - Sandbox Escape and Remote Code Execution via .git Configuration Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-26268. PoCs published by dhawaldesai.

AI-analyzed exploit summary This repository provides a detection scanner for multiple AI coding assistant vulnerabilities, including CVE-2026-26268 (Cursor). It includes a bash script (`ais.sh`) that performs 11 checks for indicators of compromise (IOCs) related to Mini Shai-Hulud, Gemini CLI RCE, and Cursor CVE-2026-26268. The scanner is designed to detect malicious configurations, hooks, and dependencies but does not include exploit code.

Description

Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection) could write to improperly protected .git settings, including git hooks, which may cause out-of-sandbox RCE next time they are triggered. No user interaction was required as Git executes these commands automatically. Fixed in version 2.5.

Exploits (1)

nomisec SCANNER
by dhawaldesai · poc
https://github.com/dhawaldesai/agentic-ioc-scanner

This repository provides a detection scanner for multiple AI coding assistant vulnerabilities, including CVE-2026-26268 (Cursor). It includes a bash script (`ais.sh`) that performs 11 checks for indicators of compromise (IOCs) related to Mini Shai-Hulud, Gemini CLI RCE, and Cursor CVE-2026-26268. The scanner is designed to detect malicious configurations, hooks, and dependencies but does not include exploit code.

Classification
Scanner 100%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Cursor, Claude Code, Gemini CLI
No auth needed
Prerequisites: access to the target system's file system · bash environment
devstral-2 · analyzed May 06, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 8.0
EPSS 0.0048
EPSS Percentile 37.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (1)
anysphere/cursor < 2.5
Published Feb 13, 2026
Tracked Since Feb 18, 2026