we_are_coded.by CODE · The world, decoded
БГ
Docker

You approve a harmless command and somebody else's code runs. The hole is in the allowlist

DockerSecurity

Docker walks through a flaw in Cursor that let hidden text change environment settings without ever asking for approval. After that, an entirely ordinary command the developer approved themselves was running somebody else's code.

In short
  • CVE-2026-22708 in Cursor: several shell built-ins slipped past the allowlist.
  • Hidden text in a README or a comment could change a setting quietly, with no prompt.
  • After that, a command you approved yourself, like git branch, ran the other thing.
Checked on19 August 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

If you run an agent that writes code, you most likely have a list. A list of the commands it may run without asking you.

Underneath that list sits one assumption: that anything dangerous will show up as a question you can refuse. That assumption is the thing that fell.

The facts: on 14 January 2026 researchers at Pillar Security disclosed CVE-2026-22708, a flaw in Cursor. When the agent runs in auto mode with an allowlist enabled, several shell built-ins execute without appearing in that list and without asking for approval. The research names export, typeset and declare specifically. Anything that could put text in front of the agent - a README file, a dependency, an issue comment - could use them to change environment variables silently. Cursor rated the flaw High and patched it in version 2.3. Docker described the case on 18 August 2026 as part five of a series on incidents involving coding agents.

Why the check saw nothing

Shell built-ins are not programs sitting on disk. The check was looking for programs on disk. So they went through without ever surfacing in front of a human.

Then comes the ordinary part. Git reads a setting that says which program shows its output. Python reads another one. Nobody thinks about these settings, which is precisely the point of the attack. You change them a minute earlier, and after that git branch does whatever you prepared for it.

The developer saw an accurate prompt, approved a genuinely harmless command, and still got somebody else's code.

There is no memory corruption here and no escalated permission. There is a gap between what you approved and what the command now means.

What I take from it

An allowlist gives a comfort it has not earned. It checks names, while the attack works on meaning. As long as you are checking strings, there will always be a way for the string to mean something else.

So the boundary should not sit at the command line. It should sit around the whole process: separate environment, cut network, rights for today's task. Then it stops mattering what the agent decided to run, because there is nowhere for it to go.

And yes, this is Docker advertising their sandboxes. The thought underneath is still right.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→Docker: Coding Agent Horror Stories, The Command You Already Approved (18.08.2026)→CVE-2026-22708 (NVD)
Original: https://wearecoded.com/en/articles/docker-komandata-koyato-veche-si-odobril.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news