Cursor CVE-2026-26268 — Autonomous AI Agents Trigger Git Hook RCE on Developer Machines
Published 2026-04-29Ingested 2026-05-25AI Engineering PracticesHigh
Summary
CVE-2026-26268, disclosed by Cursor in February 2026 and analyzed in detail by Novee's Assaf Levkovich, is a high-severity remote code execution vulnerability triggered when the Cursor AI agent autonomously runs `git checkout` against a repository containing a malicious bare-repo configuration with pre-commit hooks. The exploit requires no further user interaction — the moment the agent touches the compromised repository the hook fires and runs attacker-controlled code on the developer machine.
Radar Context
CursorGitHub Copilot
Alignment: Reinforces current position
Related Positions: AI Governance and Risk, AI-Assisted Development Tooling
cursorcve-2026-26268ai-agent-securitygit-hook-rcecoding-agent-vulnerabilityai-tool-cve-surgenovee-security