CVE-2026-22708
Cursor has a Terminal Tool Allowlist Bypass via Environment Variables
Description
Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, certain shell built-ins can still be executed without appearing in the allowlist and without requiring user approval. This allows an attacker via indirect or direct prompt injection to poison the shell environment by setting, modifying, or removing environment variables that influence trusted commands. This vulnerability is fixed in 2.3.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
- Как агент сам откроет дверь хакеру? Разбираю три реальных пробоя AI-агентов и почему обычный ред-тиминг их не найдётru·Хабр — Информационная безопасность· PoC Agno ai-ml
- Prompt injection нельзя запатчить: год «летальной триады» и лента CVE 2026 годаru·Хабр — Информационная безопасность·
- Otto Support – An MCP, Agentic-AI Security Challengeen-us·Bishop Fox· Research otto-support CTF ai-ml
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-22708 and every CVE in our database. Create a free account — no credit card required.
Create Free Account