www.manifold.security
Cursor CLI Vulnerability Allows Pre-Trust Command Execution
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A security flaw in Cursor's CLI agent enables cloned repositories to execute arbitrary commands on a developer's machine before trust verification. This vulnerability affects users who start the agent with the worktree flag, allowing commands to run without user consent or sandbox restrictions. The issue was reported by Manifold Security on July 20, 2026, and a fix was released three days later on July 23. However, the report was closed as informative, with Cursor stating no security impact was demonstrated. The flaw is similar to a previously identified vulnerability (CVE-2025-64109) that allowed remote code execution through a different mechanism. Developers are advised to update to the fixed version or disable worktree setup to mitigate risks. The lack of an official advisory means users may remain unaware of the vulnerability. Earlier builds remain vulnerable despite the patch.
Key Points: • Cursor's CLI flaw allows arbitrary command execution before trust verification. • The vulnerability affects users starting the agent with the worktree flag. • Developers must update to version 2026.07.23-e383d2b or later to mitigate risks.