Shell Environment Manipulation in Cursor Code Editor by Cursor
CVE-2026-22708
7.2HIGH
What is CVE-2026-22708?
The Cursor Code Editor, prior to version 2.3, allows for potential manipulation of the shell environment while running in Auto-Run Mode with Allowlist mode active. Attackers can leverage indirect or direct prompt injections to execute certain shell built-ins that are not adequately filtered by the allowlist. This could lead to unauthorized alterations of environment variables, which can significantly distort the execution context of trusted commands. The vulnerability has been remediated in version 2.3, emphasizing the importance of keeping software up to date to ensure protection against exploitation.
Affected Version(s)
cursor < 2.3
