Critical 9.8
CVE-2026-22708
Cursor Terminal Allowlist Bypass Vulnerability (CVE-2026-22708)
Vendor / product: Cursor
Event date: 2026-01-13
Public PoC: Yes
First tracked by RiskWire: 2026-09-06
Sources & citations (1)
- The Cursor Allowlist Bypass That Starts With a File Named curl dev.to · 2026-09-07
References
See CVE-2026-22708 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →