CVE-2026-22708

CRITICAL WAF: High
CVSS 9.8 Published: 2026-01-14
CWE-77 CWE-78 CWE-94 CWE-269 CWE-77

Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, certain shell built-ins can still be executed without appearing in the allowlist and without requiring user approval. This allows an attacker via indirect or direct prompt injection to poison the shell environment by setting, modifying, or removing environment variables that influence trusted commands. This vulnerability is fixed in 2.3.

WAF Coverage Analysis

Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution
OS Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution
Code Injection Medium WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution 933xxx - PHP Injection 934xxx - Node.js / Generic Injection
Improper Privilege Management Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
anyspherecursorup to 2.3

References

Back to CVE Database