Vulnerability Description
Cursor is a code editor built for programming with AI. In versions prior to 3.0.0, the Cursor Desktop could execute workspace-defined Claude hook commands from .claude/settings.local.json without dedicated user approval. A malicious workspace or agent-created file could configure hooks that run local commands in the user's context when an agent turn ends. This could allow sandbox escape, persistence across turns, local data access, or follow-on compromise. This issue has been fixed in version 3.0.0.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-48124?
CVE-2026-48124 is a documented vulnerability. Cursor is a code editor built for programming with AI. In versions prior to 3.0.0, the Cursor Desktop could execute workspace-defined Claude hook commands from .claude/settings.local.json without dedi...
How severe is CVE-2026-48124?
CVSS scoring is not yet available for CVE-2026-48124. Check NVD for updates.
Is there a patch for CVE-2026-48124?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.