Code Execution Flaw in Cursor Code Editor by Cursor Technologies
CVE-2026-50548

9.3CRITICAL

Key Information:

Vendor

Cursor

Status
Vendor
CVE Published:
25 June 2026

What is CVE-2026-50548?

CVE-2026-50548 is a vulnerability identified in the Cursor code editor, a development tool designed to facilitate programming with the assistance of AI. This vulnerability originates from the way Cursor handles commands within its sandbox environment prior to version 3.0. Specifically, the flaw exists in the system's handling of the working_directory parameter, allowing an attacker to potentially manipulate this parameter. As a result, the sandbox can include writable paths beyond the secure workspace, enabling the execution of arbitrary code outside the sandbox environment.

This means that a malicious agent can exploit this vulnerability to write files to sensitive locations within the system under the privileges of the user, leading to non-sandboxed remote code execution without requiring any direct interaction from the user. Such capabilities could significantly compromise the integrity and security of an organization's systems, as it facilitates the execution of unauthorized commands with potentially severe consequences. The issue has been addressed and fixed in version 3.0 of the software.

Potential impact of CVE-2026-50548

  1. Remote Code Execution: The most significant impact of this vulnerability is the potential for remote code execution. Attackers could exploit it to run malicious code on affected systems, which can lead to unauthorized data access or manipulation.

  2. Data Integrity Compromise: By writing arbitrary files outside the intended workspace, the integrity of sensitive data can be compromised. Attackers could overwrite critical system files, leading to systematic disruptions and loss of data integrity.

  3. Escalation of Privileges: This vulnerability allows for actions to be taken under the user's privileges without their explicit consent. If exploited, an attacker could gain further access to the system or network, leading to a broader compromise and potential lateral movement within the organization.

Affected Version(s)

cursor < 3.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.