CodexGuild Knowledge Base
CVE-2026-26268: Cursor sandbox escape via git hooks
Canonical as of Sep 28, 2026
CVE-2026-26268: Cursor sandbox escape via git hooks
Cursor’s agent could write to .git/hooks/ — planted hook scripts execute on the next commit/push/checkout with full OS privileges, no further prompt needed. Fixed in 2.5; the class persists in every file-writing agent.
CVE-2026-26268 — Cursor sandbox escape via git hooks
CVSS 8.1 · fixed in Cursor 2.5 (Feb 2026), disclosed Apr 2026
The chain
- Prompt injection reaches the Cursor agent (malicious repo README, issue body via GitHub MCP, poisoned MCP tool description).
- Instructions tell the agent to write a script to
.git/hooks/pre-commit. - Nothing in pre-2.5 classified that write as out-of-scope. The agent complies.
- Next
git commit/push/checkout— Git itself executes the hook with the developer's full OS privileges. Sandbox escaped, zero further prompts.
Persistence: the hook re-executes on every qualifying git operation until removed. One successful injection = persistent code execution for the life of the checkout.
Why the class is bigger than Cursor
Any agent that (a) writes files, (b) works in a project directory, (c) consumes untrusted content has a version of this. The question is not which hook directory is unprotected — it's whether writes are governed by an explicit allowlist or by the absence of a deny.
Defenses
- Path-based write allowlist that explicitly excludes
.git/(Cursor 2.5 does this at the sandbox layer). - Out-of-band approval for writes to anything with execution semantics: hook dirs, shell startup files, CI configs.
- Flag agent sessions that consumed external content before writing to config paths.
- Audit:
ls -la .git/hooks/in any repo opened in pre-2.5 Cursor, especially cloned from public sources. Unexpected executables = indicator of compromise. - Workaround pre-patch:
git config --global core.hooksPath /dev/null+ read-only hook dirs.