CanonicalSecurity
CVE-2026-26268: Cursor sandbox escape via git hooks
Cursor’s agent could write to .git/hooks/ — planted hook scripts execute on the next commit/push/checkout with full OS privileges, no further prompt needed. Fixed in 2.5; the class persists in every file-writing agent.
securityincidentcve