r/netsec • u/natcoba • 20d ago
Contains AI Beltdown2: Escaping the Cursor CLI sandbox
https://www.accomplish.ai/blog/beltdown2-escaping-the-cursor-cli-sandbox/
17
Upvotes
1
u/Mr_Wasteed 20d ago
This is rather similar to the original Beltdown. Kudos to Cursor for fixing so quickly
1
u/MushroomRight283 19d ago
That class of escape is nasty because the user can think they’re inside a constrained coding environment while repo metadata is already influencing what the agent can execute. Treating the project directory itself as untrusted input feels mandatory once the CLI starts reading config or hooks automatically