Shell Environment Manipulation in Cursor Code Editor by Cursor
CVE-2026-22708

7.2HIGH

Key Information:

Vendor

Cursor

Status
Vendor
CVE Published:
14 January 2026

What is CVE-2026-22708?

The Cursor Code Editor, prior to version 2.3, allows for potential manipulation of the shell environment while running in Auto-Run Mode with Allowlist mode active. Attackers can leverage indirect or direct prompt injections to execute certain shell built-ins that are not adequately filtered by the allowlist. This could lead to unauthorized alterations of environment variables, which can significantly distort the execution context of trusted commands. The vulnerability has been remediated in version 2.3, emphasizing the importance of keeping software up to date to ensure protection against exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

cursor < 2.3

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.