Ce mail provient de l'extérieur, restons vigilants

====================================================================

                            CERT-Renater

                Note d'Information No. 2026/VULN711
_____________________________________________________________________

DATE                : 02/07/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Cursor versions prior to 3.0.
 
====================================================================
https://github.com/cursor/cursor/security/advisories/GHSA-3p48-7v9f-v5cw
_____________________________________________________________________


Cursor Desktop sandbox escape via agent-controlled working directory
Critical
jainilajmera published GHSA-3p48-7v9f-v5cw

Software
Cursor

Affected versions
< 3.0

Patched versions
3.0

Description

Summary

Cursor runs agent terminal commands in a sandbox by default, and the
sandbox grants write access to the command's working directory. A flaw
was identified in how the agent could modify the working_directory
parameter, which could cause the sandbox to include writable paths
outside the intended workspace.


Impact

A malicious agent could set working_directory to a sensitive location
and write arbitrary files outside the workspace under the user's
privileges. This enables non-sandboxed Remote Code Execution — for
example by overwriting the cursorsandbox helper so later commands
run unsandboxed — with no user interaction beyond a benign prompt.


Remediation

Update Cursor to version 3.0. The sandbox no longer grants write access
based on an agent-controlled working directory.


Credit
Cato AI Labs

Severity
Critical

CVE ID
CVE-2026-50548

Weaknesses
No CWEs

========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
========================================================



