Cursor IDE Git Hook RCE
When an AI Coding Agent Turns Git Hooks Into Workstation Code Execution
Novee Security researcher Assaf Levkovich disclosed CVE-2026-26268 on April 28, 2026 — a high-severity arbitrary code execution flaw in Cursor IDE versions before 2.5. Unlike traditional Git hook vulnerabilities that require a user to manually run a Git command, this attack exploits agentic IDE behavior: the AI coding agent autonomously performs Git operations in response to a user's innocuous request, unknowingly triggering malicious hooks embedded in attacker-controlled repositories. Developers don't need to do anything suspicious. Asking the agent to explain a codebase is enough.
"The agent performed a Git checkout on my behalf. I only asked it to explain the project. The hook ran before I knew what happened."
— Researcher demonstration, Novee Security
CVE Details
Cursor IDE Agentic Git Hook Remote Code Execution via Embedded Bare Repository
Cursor IDE before version 2.5 allows an AI coding agent to autonomously perform Git operations — including checkouts — without user confirmation. A malicious repository can embed a bare repository containing a crafted Git hook. When the agent enters the embedded repository context and performs a checkout, the hook executes arbitrary code under the victim's user account with no additional interaction required beyond the initial clone and a routine agent request.
ROOT CAUSE
The vulnerability is the unsafe intersection of two legitimate Git features — Git hooks and bare repositories — with agentic IDE automation. Git hooks are scripts that execute at defined lifecycle points (checkout, merge, commit). Bare repositories contain only Git metadata without a working tree and can be nested inside a normal repository. When an AI agent autonomously traverses a repository and enters a nested bare repository context to perform a checkout, any hooks registered in that bare repository execute on the host system. Cursor before 2.5 did not sandbox or gate this execution path.
Attack Path
Attacker Publishes Poisoned Repository
The attacker creates a repository that appears legitimate — a library, a starter template, a code sample — and embeds a bare Git repository inside it. The bare repository contains a crafted hook (e.g., a post-checkout hook) pointing to an attacker-controlled payload.
The outer repository can pass visual inspection and static analysis. The embedded bare repository and its hooks are not surfaced by standard git log or diff views.
Victim Clones and Opens in Cursor IDE
The victim clones the repository through any standard means — Git CLI, IDE UI, or a link shared by a colleague — and opens it in Cursor IDE. At this point no code has executed. The hook is dormant until a checkout occurs inside the embedded bare repository.
Standard Git clone operations do not trigger the hook. The attack surface is specific to the agentic operation that follows.
Victim Asks the Agent an Innocuous Question
The victim asks the Cursor AI agent something routine: "Explain this codebase," "What does this project do?", or "Summarize the repository structure." The agent autonomously traverses the repository — reading files, following references, and performing Git operations — to fulfill the request.
The user has no indication that the agent will perform Git operations. "Explain this project" does not read as a dangerous instruction.
Agent Enters Embedded Bare Repository, Hook Executes
While processing the repository, the agent enters the embedded bare repository context and performs a checkout. The embedded post-checkout hook executes immediately under the victim's user account — running attacker-controlled code with full developer workstation permissions. Credentials, source code, and secrets are now accessible to the attacker.
Hook execution appears in process logs as a normal Git operation. Without endpoint detection tuned for non-interactive hook execution, this is effectively silent.
Impact
Developer Endpoint
- Arbitrary code execution at user privilege
- Credential and secret theft from workstation
- Access to in-memory tokens and SSH keys
- Persistent backdoor installation
Supply Chain
- Compromised machine can push malicious commits
- Build pipeline tampering via stolen CI tokens
- Lateral movement to code repositories and artifact stores
- Malicious code introduced upstream before review
Detection Gap
- Git hook execution blends with normal developer activity
- No visible prompt or agent warning shown to the user
- Standard Git audit logs do not flag hook execution
- Attack surface unique to agentic IDE behavior
Response Checklist
The fix ships in Cursor IDE v2.5. Patch all developer workstations running Cursor before 2.5 immediately. Treat this as a same-day emergency update — the exploit requires no elevated privileges and leaves no obvious trace.
Review process execution logs on developer workstations for Git hook invocations that occurred outside of explicit user-initiated Git commands. Look for post-checkout, post-merge, or pre-commit hooks spawned from IDE processes. Correlate with recently cloned external repositories.
Until Cursor 2.5 is deployed across all workstations, configure the IDE to disable autonomous agent Git operations when working with repositories from external or unverified sources. Treat any repository not explicitly trusted by your organization as untrusted by default.
For any workstation that ran Cursor before 2.5 and was used to open repositories from external sources, rotate all developer credentials: SSH keys, API tokens, cloud credentials, CI/CD pipeline secrets, and any credentials stored in environment variables or credential managers.
Add a pre-processing scan to your repository ingestion workflow that detects nested .git directories and bare repository structures. Block agentic IDE processing of any repository containing nested Git metadata until the structure is reviewed. Use: find . -name ".git" -not -path "./.git" to surface candidates.
Configure your EDR or endpoint monitoring to alert on Git hook scripts executed by IDE parent processes (Cursor, Electron, or Node child processes) without a corresponding interactive Git command from the terminal. Non-interactive hook execution is anomalous and should be treated as a signal of agentic exploitation or supply-chain tampering.
Establish a formal distinction between passive agent operations (reading, summarizing, explaining) and autonomous operations (executing commands, performing Git operations, writing files). Require explicit user confirmation before the agent performs any autonomous action that modifies state or spawns processes. Document this policy and enforce it through IDE configuration or custom rules.
Governance Framework
Explicit Trust Prompts
Agent operations that spawn processes, perform Git checkouts, or modify the filesystem should require an explicit trust confirmation — distinct from the user's original natural-language request. "Explain this project" should not implicitly authorize code execution.
Repository Trust Boundaries
Establish formal trust tiers for repositories: internal, verified external, and unverified external. Agentic IDE operations should be scoped to the trust level of the repository in use. Unverified repositories should get read-only agent access only.
Least-Privilege Agent Sandboxing
Run agentic IDE sessions in sandboxed environments with restricted filesystem access, no network egress to non-allowlisted destinations, and process execution controls. Developer experience and security are not mutually exclusive — enforce isolation at the session level.
Supply-Chain Awareness
Treat third-party repositories as supply-chain artifacts. Require peer review before opening any external repository in an agentic IDE on a workstation with access to production credentials or CI/CD pipelines.
Hook Execution Monitoring
Git hooks are executable scripts that run with developer permissions. Treat unexpected hook execution with the same urgency as unexpected process execution. Add hook invocation visibility to your developer endpoint monitoring baseline.
Prompt-Injection Testing
Include agentic IDE exploitation scenarios in security reviews: can repository content instruct the agent to perform operations the user did not explicitly request? Test for instruction injection via README files, code comments, commit messages, and embedded metadata.
References
[1] Novee Security
Assaf Levkovich — Primary researcher and responsible disclosure coordinator with Anysphere. April 28, 2026.
[2] NVD
CVE-2026-26268 — Cursor IDE Agentic Git Hook Remote Code Execution
[3] GitHub Security Advisory
GHSA-8pcm-8jpx-hv8r — Cursor IDE before 2.5 arbitrary code execution via embedded bare repository Git hook
[4] The Hacker News
Coverage of CVE-2026-26268 and the broader risk of agentic IDE execution surfaces. April 30, 2026.
[5] NeuraCybIntel
Technical analysis and threat landscape context. May 4, 2026.