A security vulnerability, CVE-2026-22708, has been identified in the Cursor AI coding agent's terminal allowlist. This bypass allows a malicious file within a project directory to execute arbitrary commands by exploiting how the terminal resolves commands. The vulnerability arises when a script with a common command name, like 'curl', is present in the project's directory, leading the system to execute the local script instead of the intended system binary. AI
IMPACT This vulnerability highlights security risks for AI coding agents that execute shell commands, potentially leading to wider adoption of security checks for such tools.
RANK_REASON The item details a specific vulnerability and a tool's response to it, rather than a new product release or major research finding.
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →