Shell Environment Manipulation in Cursor Code Editor by Cursor
CVE-2026-22708
What is CVE-2026-22708?
The Cursor Code Editor, prior to version 2.3, allows for potential manipulation of the shell environment while running in Auto-Run Mode with Allowlist mode active. Attackers can leverage indirect or direct prompt injections to execute certain shell built-ins that are not adequately filtered by the allowlist. This could lead to unauthorized alterations of environment variables, which can significantly distort the execution context of trusted commands. The vulnerability has been remediated in version 2.3, emphasizing the importance of keeping software up to date to ensure protection against exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
cursor < 2.3
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
