High · CVSS 8.1 April 28, 2026 · Novee Security

Cursor IDE Git Hook RCE

When an AI Coding Agent Turns Git Hooks Into Workstation Code Execution

Novee Security researcher Assaf Levkovich disclosed CVE-2026-26268 on April 28, 2026 — a high-severity arbitrary code execution flaw in Cursor IDE versions before 2.5. Unlike traditional Git hook vulnerabilities that require a user to manually run a Git command, this attack exploits agentic IDE behavior: the AI coding agent autonomously performs Git operations in response to a user's innocuous request, unknowingly triggering malicious hooks embedded in attacker-controlled repositories. Developers don't need to do anything suspicious. Asking the agent to explain a codebase is enough.

1 CVE
8.1 CVSS Score
RCE Impact
v2.5+ Fixed In

"The agent performed a Git checkout on my behalf. I only asked it to explain the project. The hook ran before I knew what happened."

— Researcher demonstration, Novee Security

CVE Details

CVE-2026-26268 High · 8.1 Arbitrary Code Execution

Cursor IDE Agentic Git Hook Remote Code Execution via Embedded Bare Repository

Cursor IDE before version 2.5 allows an AI coding agent to autonomously perform Git operations — including checkouts — without user confirmation. A malicious repository can embed a bare repository containing a crafted Git hook. When the agent enters the embedded repository context and performs a checkout, the hook executes arbitrary code under the victim's user account with no additional interaction required beyond the initial clone and a routine agent request.

Affected: Cursor IDE / Anysphere, versions before 2.5  ·  GHSA: GHSA-8pcm-8jpx-hv8r  ·  Impact: Arbitrary code execution on developer workstations, credential theft, supply-chain compromise.

ROOT CAUSE

The vulnerability is the unsafe intersection of two legitimate Git features — Git hooks and bare repositories — with agentic IDE automation. Git hooks are scripts that execute at defined lifecycle points (checkout, merge, commit). Bare repositories contain only Git metadata without a working tree and can be nested inside a normal repository. When an AI agent autonomously traverses a repository and enters a nested bare repository context to perform a checkout, any hooks registered in that bare repository execute on the host system. Cursor before 2.5 did not sandbox or gate this execution path.

Attack Path

1

Attacker Publishes Poisoned Repository

The attacker creates a repository that appears legitimate — a library, a starter template, a code sample — and embeds a bare Git repository inside it. The bare repository contains a crafted hook (e.g., a post-checkout hook) pointing to an attacker-controlled payload.

The outer repository can pass visual inspection and static analysis. The embedded bare repository and its hooks are not surfaced by standard git log or diff views.

2

Victim Clones and Opens in Cursor IDE

The victim clones the repository through any standard means — Git CLI, IDE UI, or a link shared by a colleague — and opens it in Cursor IDE. At this point no code has executed. The hook is dormant until a checkout occurs inside the embedded bare repository.

Standard Git clone operations do not trigger the hook. The attack surface is specific to the agentic operation that follows.

3

Victim Asks the Agent an Innocuous Question

The victim asks the Cursor AI agent something routine: "Explain this codebase," "What does this project do?", or "Summarize the repository structure." The agent autonomously traverses the repository — reading files, following references, and performing Git operations — to fulfill the request.

The user has no indication that the agent will perform Git operations. "Explain this project" does not read as a dangerous instruction.

4

Agent Enters Embedded Bare Repository, Hook Executes

While processing the repository, the agent enters the embedded bare repository context and performs a checkout. The embedded post-checkout hook executes immediately under the victim's user account — running attacker-controlled code with full developer workstation permissions. Credentials, source code, and secrets are now accessible to the attacker.

Hook execution appears in process logs as a normal Git operation. Without endpoint detection tuned for non-interactive hook execution, this is effectively silent.

Impact

Developer Endpoint

  • Arbitrary code execution at user privilege
  • Credential and secret theft from workstation
  • Access to in-memory tokens and SSH keys
  • Persistent backdoor installation

Supply Chain

  • Compromised machine can push malicious commits
  • Build pipeline tampering via stolen CI tokens
  • Lateral movement to code repositories and artifact stores
  • Malicious code introduced upstream before review

Detection Gap

  • Git hook execution blends with normal developer activity
  • No visible prompt or agent warning shown to the user
  • Standard Git audit logs do not flag hook execution
  • Attack surface unique to agentic IDE behavior

Response Checklist

STEP 01 Upgrade Cursor IDE to Version 2.5 or Later Immediate

The fix ships in Cursor IDE v2.5. Patch all developer workstations running Cursor before 2.5 immediately. Treat this as a same-day emergency update — the exploit requires no elevated privileges and leaves no obvious trace.

STEP 02 Audit Developer Endpoints for Suspicious Hook Execution Immediate

Review process execution logs on developer workstations for Git hook invocations that occurred outside of explicit user-initiated Git commands. Look for post-checkout, post-merge, or pre-commit hooks spawned from IDE processes. Correlate with recently cloned external repositories.

STEP 03 Disable Autonomous Agent Actions for Untrusted Repositories Immediate

Until Cursor 2.5 is deployed across all workstations, configure the IDE to disable autonomous agent Git operations when working with repositories from external or unverified sources. Treat any repository not explicitly trusted by your organization as untrusted by default.

STEP 04 Rotate Exposed Secrets on Potentially Affected Machines Immediate

For any workstation that ran Cursor before 2.5 and was used to open repositories from external sources, rotate all developer credentials: SSH keys, API tokens, cloud credentials, CI/CD pipeline secrets, and any credentials stored in environment variables or credential managers.

STEP 05 Screen Repositories for Nested .git Structures Before Agentic Processing Urgent

Add a pre-processing scan to your repository ingestion workflow that detects nested .git directories and bare repository structures. Block agentic IDE processing of any repository containing nested Git metadata until the structure is reviewed. Use: find . -name ".git" -not -path "./.git" to surface candidates.

STEP 06 Implement Endpoint Detection for Non-Interactive Hook Execution Urgent

Configure your EDR or endpoint monitoring to alert on Git hook scripts executed by IDE parent processes (Cursor, Electron, or Node child processes) without a corresponding interactive Git command from the terminal. Non-interactive hook execution is anomalous and should be treated as a signal of agentic exploitation or supply-chain tampering.

STEP 07 Define Policy for Autonomous vs. Passive Agent Operations Important

Establish a formal distinction between passive agent operations (reading, summarizing, explaining) and autonomous operations (executing commands, performing Git operations, writing files). Require explicit user confirmation before the agent performs any autonomous action that modifies state or spawns processes. Document this policy and enforce it through IDE configuration or custom rules.

Governance Framework

Explicit Trust Prompts

Agent operations that spawn processes, perform Git checkouts, or modify the filesystem should require an explicit trust confirmation — distinct from the user's original natural-language request. "Explain this project" should not implicitly authorize code execution.

Repository Trust Boundaries

Establish formal trust tiers for repositories: internal, verified external, and unverified external. Agentic IDE operations should be scoped to the trust level of the repository in use. Unverified repositories should get read-only agent access only.

Least-Privilege Agent Sandboxing

Run agentic IDE sessions in sandboxed environments with restricted filesystem access, no network egress to non-allowlisted destinations, and process execution controls. Developer experience and security are not mutually exclusive — enforce isolation at the session level.

Supply-Chain Awareness

Treat third-party repositories as supply-chain artifacts. Require peer review before opening any external repository in an agentic IDE on a workstation with access to production credentials or CI/CD pipelines.

Hook Execution Monitoring

Git hooks are executable scripts that run with developer permissions. Treat unexpected hook execution with the same urgency as unexpected process execution. Add hook invocation visibility to your developer endpoint monitoring baseline.

Prompt-Injection Testing

Include agentic IDE exploitation scenarios in security reviews: can repository content instruct the agent to perform operations the user did not explicitly request? Test for instruction injection via README files, code comments, commit messages, and embedded metadata.

References

[1] Novee Security

Assaf Levkovich — Primary researcher and responsible disclosure coordinator with Anysphere. April 28, 2026.

[2] NVD

CVE-2026-26268 — Cursor IDE Agentic Git Hook Remote Code Execution

[3] GitHub Security Advisory

GHSA-8pcm-8jpx-hv8r — Cursor IDE before 2.5 arbitrary code execution via embedded bare repository Git hook

[4] The Hacker News

Coverage of CVE-2026-26268 and the broader risk of agentic IDE execution surfaces. April 30, 2026.

[5] NeuraCybIntel

Technical analysis and threat landscape context. May 4, 2026.

Primary source: Novee Security disclosure by Assaf Levkovich, April 28, 2026. Coordinated responsible disclosure with Anysphere prior to publication. This advisory is an independent defensive guide produced by Spectreworks AI for educational purposes only and is not affiliated with Novee Security or Anysphere.