Mark RadarMARK RADAR
EN

Sandbox Flaws Let Cursor, Codex and Gemini Agents Reach Host Systems

1 reports · First detected 2026-07-21 · Last active 2026-07-21

AI coding agents can edit files and run shell commands, making sandboxing a critical barrier against mistakes, prompt injection and malicious repositories. Pillar Security said Cursor, OpenAI’s Codex CLI, Google’s Gemini CLI and Antigravity exposed indirect paths around that boundary. Rather than breaking isolation directly, an agent could alter workspace settings, Git configuration or Python virtual-environment files that trusted tools later execute outside the sandbox; in some setups, Docker could also provide access to the host.

The findings were reported on July 21, 2026. Cursor’s Python virtual-environment flaw affected releases before 3.1.2 and was fixed in 3.1.2, while CVE-2026-48124 affected Cursor Desktop 2.4.37 and was patched in 3.0.0. OpenAI corrected Codex CLI’s incomplete validation of supposedly safe Git commands in version 0.95.0. Pillar also described a macOS scenario involving Docker Desktop, Dev Containers CLI and network-enabled Auto-Run Sandbox mode that could let an agent access a user’s home directory and run host commands without another approval prompt.

All Coverage

1 original reports

The Backstory

The history behind this event
Unpatched Cursor Flaw Lets Malicious Repositories Run Code2026-07-20 · 1 reports · similarity 0.81

Cursor, a widely used AI coding assistant, integrates closely with local development environments to help programmers navigate and generate code. Cybersecurity firm Mindgard said that integration creates a potential attack path when the tool handles Git executables inside an untrusted project. The finding highlights a broader software-supply-chain risk as AI development tools gain access to source code, command-line utilities and other resources on developers’ machines.

Mindgard disclosed an unpatched Cursor vulnerability that allows an attacker to place a malicious git.exe file in a project’s root directory. Opening the booby-trapped repository could then trigger arbitrary code execution without an additional deliberate launch by the developer. No patched release was available as of the report’s publication. Security specialists advised restricting executable searches to approved working directories and opening unfamiliar repositories inside a virtual machine, container or other isolated environment.

Cursor Security Flaws Allow Sandbox Bypass and Arbitrary Code Execution2026-07-02 · 1 reports · similarity 0.88

Cursor is a widely used AI coding tool that can read project content and invoke system functions, making its sandbox an important defense for isolating untrusted instructions. Cato Networks said prompt injection that crosses this boundary could place malicious code directly inside development environments, putting source code, credentials and companies’ internal systems at risk.

Cato Networks security researchers recently disclosed two critical vulnerabilities collectively dubbed “DuneSlide.” Attackers could launch a prompt-injection attack when a victim processes malicious content, bypassing Cursor’s sandbox and executing arbitrary system commands. Cursor patched the flaws in version 3.0. As of the disclosure, the company had not reported the number of affected users or the value of any actual losses. Users should upgrade as soon as possible.

Cursor Mobile Launches, Taking AI Coding Agents to the iPhone2026-06-30 · 2 reports · similarity 0.82

Anysphere’s Cursor is best known as a desktop AI code editor whose agents can understand codebases and perform coding, debugging and testing tasks. Cursor Mobile brings that workflow to the iPhone, freeing engineers from their computers and shifting their focus from writing code line by line to assigning tasks, reviewing changes and approving results.

Cursor announced the public beta of its iOS app on June 29, 2026, making it available across all paid plans. The App Store lists the app as free to download with in-app purchases. Users can select a repo and launch a cloud agent, issue instructions by voice or slash command, and use Remote Control to take over a desktop agent. They can also track progress, receive push notifications, review diffs and merge PRs directly.

CursorJacking Design Flaw in AI Code Editor Could Expose Developers’ API Keys2026-04-30 · 1 reports · similarity 0.82

Cursor, an AI code editor developed by Anysphere, uses models and extensions to assist with software development and debugging. Cybersecurity research firm LayerX said Cursor stores API keys and connection tokens in a local SQLite database, potentially putting developers’ cloud services, source code and enterprise systems at risk if access controls are inadequate.

LayerX recently disclosed a design flaw dubbed “CursorJacking” that allows malicious third-party extensions to read Cursor’s local database and steal API keys and connection tokens. As of July 20, 2026, Anysphere had not announced a patch, a remediation date or the amount of any losses. Users should avoid installing extensions from unknown sources for now.

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)