www.manifold.security Cursor CLI Vulnerability Allows Pre-Trust Command Execution
Article Content
- •Cursor's CLI flaw allows arbitrary command execution before trust verification.
- •The vulnerability affects users starting the agent with the worktree flag.
- •Developers must update to version 2026.07.23-e383d2b or later to mitigate risks.
A security flaw in Cursor's CLI agent enables cloned repositories to execute arbitrary commands on a developer's machine before trust verification. This vulnerability affects users who start the agent with the worktree flag, allowing commands to run without user consent or sandbox restrictions. The issue was reported by Manifold Security on July 20, 2026, and a fix was released three days later on July 23. However, the report was closed as informative, with Cursor stating no security impact was demonstrated. The flaw is similar to a previously identified vulnerability (CVE-2025-64109) that allowed remote code execution through a different mechanism. Developers are advised to update to the fixed version or disable worktree setup to mitigate risks. The lack of an official advisory means users may remain unaware of the vulnerability. Earlier builds remain vulnerable despite the patch.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Cursor and CVE-2025-64109 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…