Cursor closes command execution gap before workspace trust
Cursor has patched a security flaw in its command-line coding agent that allowed a malicious repository to execute commands on a developer’s computer before the user was asked whether the workspace should be trusted. The weakness affected Cursor CLI’s worktree feature and could be triggered when a user launched the agent with the -w option inside a repository containing a specially crafted.…
Cursor has resolved a security vulnerability in its command-line coding tool that allowed malicious repositories to execute commands on developers' computers before they were prompted to trust the workspace. The flaw impacted Cursor CLI's worktree feature and could be exploited when launching the agent with the -w option inside a compromised repository containing a specially crafted cursor/worktrees.json file.
This file could specify a shell command to be executed during worktree setup, preceding Cursor's Workspace Trust prompt. Researchers disclosed the issue on July 20, leading Cursor to release cursor-agent build 2026.07.23-e383d2b on July 23. The update altered the sequence so that the trust prompt appeared before the setup command, preventing pre-trust execution.
Manifold Security confirmed the vulnerability affected older builds, enabling arbitrary shell commands to run with user privileges. Cursor's isolation in worktree functionality and sandbox handling contributed to the risk, but the July 23 update mitigated the issue. Users are advised to use the corrected version or later releases to maintain security.
Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.