logo

Cursor AI Coding Agent Vulnerability Lets Attackers Run Code on Developers’ Machines

ID: 8882034b-a8b9-5de0-bcfa-fa84beb90b05

STIX ID: report--8882034b-a8b9-5de0-bcfa-fa84beb90b05

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Mayura Kathir

...
...

A high-severity vulnerability (CVE-2026-26268) in Cursor’s AI-powered coding agent can be exploited by embedding a malicious bare Git repository with a pre-commit hook inside an otherwise legitimate project; when the agent autonomously performs Git operations (e.g., checkout), the hook can execute attacker-controlled code on a developer machine without user interaction. The issue was responsibly disclosed and remediated, and the report urges treating developer environments as high-value targets, auditing AI tools for untrusted inputs, and reviewing repository hooks and configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.