logo

Cursor AI IDE vulnerability allows code execution via hidden Git hooks

ID: c9b5482d-f4db-5c7b-a40c-2b1d4110807b

STIX ID: report--c9b5482d-f4db-5c7b-a40c-2b1d4110807b

Feed Name: HackRead

Threat Score
80/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Deeba Ahmed

...
...

**Executive summary:** Researchers from Novee disclosed CVE-2026-26268, a CVSS 8.1 arbitrary code execution vulnerability in the Cursor AI-powered IDE where hidden pre-commit Git hooks embedded in nested bare repositories can cause the AI agent to run attacker-controlled code upon cloning a repository; a fix was applied in February 2026 and details were disclosed on April 28, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.