Intelligence
AEV-2026-0023

Cursor sandbox write scope expanded by an agent controlled working directory (CVE-2026-50548)

In Cursor versions before 3.0, the terminal sandbox granted write access based on a command's working directory, and working_directory was itself a parameter the agent's tool call could set, so an agent could cause the sandbox to include writable paths outside the intended workspace. Disclosed by Cursor and credited to Cato AI Labs on 5 June 2026, patched in 3.0, with no evidence of exploitation in the wild found by this record.

AESS 7.2 highConfirmedStatus: resolvedEvent: 5 June 2026Execution AuthorityEnvironment Boundaries

Affected

Organisation
Cursor (Anysphere)
Product
Cursor (agent sandbox: working directory scope)
Component
Terminal sandbox write scope policy, built in part from the working_directory tool parameter
Versions
Cursor before 3.0; fixed in 3.0
Configurations
Default sandboxed terminal command execution

Execution authority facts

Fields the evidence does not establish are shown as unknown rather than guessed.

Intended task
An AI coding agent running terminal commands inside Cursor's default sandbox
Agent
Cursor Agent
Delegating actor
unknown
Action
Set a non default working_directory on a terminal tool call, which the sandbox's own write scope policy incorporated, then wrote to a path outside the intended workspace
Target resource
Paths outside the intended workspace reachable through the agent chosen working_directory, up to overwriting the cursorsandbox helper per Cursor's own advisory
Environment
The user's own machine running Cursor's default sandboxed terminal tool
Credentials used
unknown
Privileges available
The user's own account privileges, once the cursorsandbox helper itself was overwritten
Authority presented
A terminal tool call carrying an agent chosen working_directory parameter
Authority required
Authority to write outside the workspace the sandbox was configured to constrain the agent to
Applicable policy
Cursor's sandbox write scope policy, built in part from the command's working directory
Approval mechanism
unknown
Required approver
unknown
Independent approval
no
Action binding
The sandbox's own writable scope was derived from a value the same tool call supplied, rather than independently checked against a fixed parent grant
Sequence context
Cato AI Labs describes zero click prompt injection, content the agent reads on a user's behalf such as an MCP response or a web search result, as one path by which the agent could reach the parameter with no user action beyond a benign prompt

Impact

Consequence
Arbitrary file writes outside the workspace, extending to non sandboxed remote code execution by overwriting the cursorsandbox helper, per Cursor's own advisory
Reach
single
Reversibility
unknown
Detectability
silent
Propagation
potential
Recovery
Fixed by no longer deriving sandbox write scope from the agent controlled working_directory; no way described to reverse a write or a helper overwrite already made before the patch

Evidence

Primary sources

Supporting sources

Reproduction status
Confirmed directly in Cursor's own advisory, credited to Cato AI Labs. A demonstrated zero click exploit chain is described in corroborated reporting on Cato AI Labs' own DuneSlide research, not read directly from Cato's own page in this session.
Evidence state
Confirmed

Known unknowns

  • Whether the flaw was triggered against a real deployment before the fix shipped, beyond Cato AI Labs' own demonstrated research.
  • The exact date Cursor 3.0 itself shipped was not independently confirmed from a source this record could read directly.

Limitations

  • Cato Networks' own DuneSlide article could not be fetched directly in this session; its account is corroborated through multiple independently phrased web searches converging on consistent detail across named independent outlets, not through a direct read of Cato's own page.
  • Neither GHSA advisory for this discovery backfill publishes a numeric CVSS score or a CWE classification; a CVSS score of 9.8 is reported consistently in corroborating search results but is not confirmed from Cursor's own advisory text.

Claim provenance