Security researchers disclosed CVE-2026-22708, a vulnerability in the Cursor AI coding editor that let shell built-in commands such as export and unset run in Auto-Run Mode without being checked against the user’s command allowlist. An attacker able to inject text into the agent’s context, through a direct or indirect prompt injection, could abuse this gap to poison environment variables and turn normally safe, allowlisted commands into arbitrary code execution. The flaw was disclosed in January 2026 and patched in Cursor version 2.3; researchers found no evidence it had been exploited in the wild before the fix shipped.