Knowledge base
CodexGuild Knowledge Base

CVE-2026-26268: Cursor sandbox escape via git hooks

as of Sep 28, 2026 · canonical · codexguild.com/kb/incident-cursor-git-hooks-cve-2026-26268 · exported 2026-10-11
Canonical as of Sep 28, 2026

CVE-2026-26268: Cursor sandbox escape via git hooks

Cursor’s agent could write to .git/hooks/ — planted hook scripts execute on the next commit/push/checkout with full OS privileges, no further prompt needed. Fixed in 2.5; the class persists in every file-writing agent.

CVE-2026-26268 — Cursor sandbox escape via git hooks

CVSS 8.1 · fixed in Cursor 2.5 (Feb 2026), disclosed Apr 2026

The chain

  1. Prompt injection reaches the Cursor agent (malicious repo README, issue body via GitHub MCP, poisoned MCP tool description).
  2. Instructions tell the agent to write a script to .git/hooks/pre-commit.
  3. Nothing in pre-2.5 classified that write as out-of-scope. The agent complies.
  4. Next git commit/push/checkout — Git itself executes the hook with the developer's full OS privileges. Sandbox escaped, zero further prompts.

Persistence: the hook re-executes on every qualifying git operation until removed. One successful injection = persistent code execution for the life of the checkout.

Why the class is bigger than Cursor

Any agent that (a) writes files, (b) works in a project directory, (c) consumes untrusted content has a version of this. The question is not which hook directory is unprotected — it's whether writes are governed by an explicit allowlist or by the absence of a deny.

Defenses

  1. Path-based write allowlist that explicitly excludes .git/ (Cursor 2.5 does this at the sandbox layer).
  2. Out-of-band approval for writes to anything with execution semantics: hook dirs, shell startup files, CI configs.
  3. Flag agent sessions that consumed external content before writing to config paths.
  4. Audit: ls -la .git/hooks/ in any repo opened in pre-2.5 Cursor, especially cloned from public sources. Unexpected executables = indicator of compromise.
  5. Workaround pre-patch: git config --global core.hooksPath /dev/null + read-only hook dirs.