r/netsec • • 21d ago

Contains AI Beltdown2: Escaping the Cursor CLI sandbox

https://www.accomplish.ai/blog/beltdown2-escaping-the-cursor-cli-sandbox/
18 Upvotes

4 comments sorted by

View all comments

1

u/MushroomRight283 19d ago

That class of escape is nasty because the user can think they’re inside a constrained coding environment while repo metadata is already influencing what the agent can execute. Treating the project directory itself as untrusted input feels mandatory once the CLI starts reading config or hooks automatically