New Cursor CLI sandbox escape variant runs arbitrary code on your Mac
EdenEmarco177 · x · 2026-09-13
Security researcher orcaman disclosed a new variant of the previously shared Beltdown vulnerability: after the Cursor team shipped a fix in about a week, the researcher demonstrates escaping Cursor CLI's sandbox to run arbitrary code on a Mac. The team was credited for the fast prior fix; this new bypass underscores local security risks of AI coding tools.
More from coding & agent
- Clipboard-Automator: open-source ComfyUI nodes turn your OS clipboard into a zero-click pipeline — kastelan77 · 2026-09-13
- Dev ships obsideo-mcp, an MCP encrypted storage server agents can verify with signed possession proofs — Electrical_Offer5667 · 2026-09-13
- Prompt Injection Detector: a 6-point checklist for scanning untrusted text before it hits your LLM — blaizedsouza · 2026-09-13
- Trading agent's reflection loop was learning from noise: judging theses apart from PnL fixed half of it — ExplorerEconomy8233 · 2026-09-13
- Clipboard-Automator: open-source ComfyUI nodes that turn your clipboard into a hands-off pipeline — kastelan77 · 2026-09-13
- A trick for efficient multi-agent runs: dispatch work, end turn, get woken up on completion — pvncher · 2026-09-13