CVE-2026-50549 is a critical arbitrary file write and sandbox escape vulnerability in Cursor, an AI-assisted code editor, affecting versions prior to 3.0. Before performing a Write operation, Cursor attempts to canonicalize the destination path to verify that the resolved target remains داخل the workspace boundary. If canonicalization fails, however, the application falls back to the original, unvalidated path and proceeds with the write without requiring approval. An attacker-controlled or malicious agent can exploit this logic by creating a symbolic link inside the workspace that points to a location outside the workspace, then causing canonicalization to fail, such as by targeting a non-existent destination or removing read permission from part of the path. The resulting write follows the symlink and reaches an arbitrary external location under the user’s privileges, bypassing Cursor’s intended workspace and sandbox protections.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A symlink-handling vulnerability in Cursor that can mislead users during approval and cause writes to the resolved destination outside the workspace.
A symlink-handling vulnerability in Cursor that can allow file writes outside its sandbox/workspace while misleading the user by showing only the decoy filename rather than the resolved symlink target.
The Cursor-specific GhostApproval vulnerability in which the UI showed the symlink path but the backend followed the resolved target, allowing unauthorized writes outside the workspace.
Vendor-assigned CVE for the GhostApproval-related flaw fixed by Cursor in version 3.0.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.