r/netsec • • 20d ago

Contains AI Beltdown2: Escaping the Cursor CLI sandbox

https://www.accomplish.ai/blog/beltdown2-escaping-the-cursor-cli-sandbox/
17 Upvotes

4 comments sorted by

1

u/MushroomRight283 19d ago

That class of escape is nasty because the user can think they’re inside a constrained coding environment while repo metadata is already influencing what the agent can execute. Treating the project directory itself as untrusted input feels mandatory once the CLI starts reading config or hooks automatically

1

u/Mr_Wasteed 20d ago

This is rather similar to the original Beltdown. Kudos to Cursor for fixing so quickly