AEV-2026-0023
Cursor sandbox write scope expanded by an agent controlled working directory (CVE-2026-50548)
In Cursor versions before 3.0, the terminal sandbox granted write access based on a command's working directory, and working_directory was itself a parameter the agent's tool call could set, so an agent could cause the sandbox to include writable paths outside the intended workspace. Disclosed by Cursor and credited to Cato AI Labs on 5 June 2026, patched in 3.0, with no evidence of exploitation in the wild found by this record.
Affected
- Organisation
- Cursor (Anysphere)
- Product
- Cursor (agent sandbox: working directory scope)
- Component
- Terminal sandbox write scope policy, built in part from the working_directory tool parameter
- Versions
- Cursor before 3.0; fixed in 3.0
- Configurations
- Default sandboxed terminal command execution
Execution authority facts
Fields the evidence does not establish are shown as unknown rather than guessed.
- Intended task
- An AI coding agent running terminal commands inside Cursor's default sandbox
- Agent
- Cursor Agent
- Delegating actor
- unknown
- Action
- Set a non default working_directory on a terminal tool call, which the sandbox's own write scope policy incorporated, then wrote to a path outside the intended workspace
- Target resource
- Paths outside the intended workspace reachable through the agent chosen working_directory, up to overwriting the cursorsandbox helper per Cursor's own advisory
- Environment
- The user's own machine running Cursor's default sandboxed terminal tool
- Credentials used
- unknown
- Privileges available
- The user's own account privileges, once the cursorsandbox helper itself was overwritten
- Authority presented
- A terminal tool call carrying an agent chosen working_directory parameter
- Authority required
- Authority to write outside the workspace the sandbox was configured to constrain the agent to
- Applicable policy
- Cursor's sandbox write scope policy, built in part from the command's working directory
- Approval mechanism
- unknown
- Required approver
- unknown
- Independent approval
- no
- Action binding
- The sandbox's own writable scope was derived from a value the same tool call supplied, rather than independently checked against a fixed parent grant
- Sequence context
- Cato AI Labs describes zero click prompt injection, content the agent reads on a user's behalf such as an MCP response or a web search result, as one path by which the agent could reach the parameter with no user action beyond a benign prompt
Impact
- Consequence
- Arbitrary file writes outside the workspace, extending to non sandboxed remote code execution by overwriting the cursorsandbox helper, per Cursor's own advisory
- Reach
- single
- Reversibility
- unknown
- Detectability
- silent
- Propagation
- potential
- Recovery
- Fixed by no longer deriving sandbox write scope from the agent controlled working_directory; no way described to reverse a write or a helper overwrite already made before the patch
Evidence
Primary sources
- Cursor Desktop sandbox escape via agent-controlled working directory (CVE-2026-50548) (Cursor (Anysphere))
Supporting sources
- DuneSlide: Two Critical RCE vulnerabilities via Zero-Click Prompt Injection in Cursor IDE (Cato Networks)
- Reproduction status
- Confirmed directly in Cursor's own advisory, credited to Cato AI Labs. A demonstrated zero click exploit chain is described in corroborated reporting on Cato AI Labs' own DuneSlide research, not read directly from Cato's own page in this session.
- Evidence state
- Confirmed
Known unknowns
- Whether the flaw was triggered against a real deployment before the fix shipped, beyond Cato AI Labs' own demonstrated research.
- The exact date Cursor 3.0 itself shipped was not independently confirmed from a source this record could read directly.
Limitations
- Cato Networks' own DuneSlide article could not be fetched directly in this session; its account is corroborated through multiple independently phrased web searches converging on consistent detail across named independent outlets, not through a direct read of Cato's own page.
- Neither GHSA advisory for this discovery backfill publishes a numeric CVSS score or a CWE classification; a CVSS score of 9.8 is reported consistently in corroborating search results but is not confirmed from Cursor's own advisory text.
Claim provenance
- verified
Cursor's own advisory, fetched directly, states the mechanism, assigns CVE-2026-50548, records the affected and fixed versions, and credits Cato AI Labs.
The Sandbox Asked the Agent Where the Boundary Should Be. - independent-reporting
Cato AI Labs' own DuneSlide research names the zero click prompt injection delivery path and the cursorsandbox overwrite chain. Cato's own site could not be fetched directly in this session; this basis rests on corroborated search reporting rather than a direct read.
The Sandbox Asked the Agent Where the Boundary Should Be.
