Threat · curated 10 Aug 2026

Cursor 3.0.0 Fixes CVE-2026-48124 Sandbox-to-Host Code Execution

Coverage timeline

21 Jul 2026windowsforum.com

Single-source advisory — first reported, latest, and curated coincide.

Why it matters

CVE-2026-48124 shows that the sandbox reassurance around AI coding agents is illusory when trusted host tools execute agent-written files, exposing developer endpoints to code execution across multiple widely used agentic coding tools.

Security researchers disclosed CVE-2026-48124, a class of sandbox-to-host code execution weaknesses affecting AI coding agents including Cursor, OpenAI Codex CLI, Google Gemini CLI, and Antigravity. The agents remained technically confined, but files they created or modified were later consumed by trusted host applications, extensions, task runners, Git integrations, Python tooling, hooks, or Docker services, yielding code execution beyond the sandbox without exploiting the OS isolation itself. Cursor 3.0.0 ships fixes for the issue.