Cursor CLI Vulnerability Allows Pre-Trust Command Execution

Cursor CLI Vulnerability Allows Pre-Trust Command Execution

First seen 11 Aug 2026, 15:02 UTC Infosecurity-Magazinewww.manifold.security 73% similarity 54.9

Article Content

Browse articles
ThreatCluster

A security flaw in Cursor's CLI agent enables cloned repositories to execute arbitrary commands on a developer's machine before trust verification. This vulnerability affects users who start the agent with the worktree flag, allowing commands to run without user consent or sandbox restrictions. The issue was reported by Manifold Security on July 20, 2026, and a fix was released three days later on July 23. However, the report was closed as informative, with Cursor stating no security impact was demonstrated. The flaw is similar to a previously identified vulnerability (CVE-2025-64109) that allowed remote code execution through a different mechanism. Developers are advised to update to the fixed version or disable worktree setup to mitigate risks. The lack of an official advisory means users may remain unaware of the vulnerability. Earlier builds remain vulnerable despite the patch.

Key Points: • Cursor's CLI flaw allows arbitrary command execution before trust verification. • The vulnerability affects users starting the agent with the worktree flag. • Developers must update to version 2026.07.23-e383d2b or later to mitigate risks.

ThreatCluster AI How this analysis works

Timeline

2025-11-04
CVE-2025-64109 published
Cursor fixed a vulnerability allowing remote code execution via a repository-supplied file.
Article 1
2026-07-20
Vulnerability reported to Cursor
Manifold Security reported the pre-trust execution flaw in Cursor's CLI agent.
Article 2
2026-07-23
Cursor releases fix for vulnerability
Cursor shipped a patch that gated the setup command behind the Workspace Trust prompt.
Article 1
2026-07-29
Report closed as informative
Cursor closed the vulnerability report, stating no security impact was demonstrated.
Article 2
2026-08-10
Manifold publishes findings
Manifold Security published their findings on the vulnerability, highlighting its risks.
Article 2

Community

Browse all →

Tracked Entities in This Story