Docker walks through a flaw in Cursor that let hidden text change environment settings without ever asking for approval. After that, an entirely ordinary command the developer approved themselves was running somebody else's code.
- CVE-2026-22708 in Cursor: several shell built-ins slipped past the allowlist.
- Hidden text in a README or a comment could change a setting quietly, with no prompt.
- After that, a command you approved yourself, like git branch, ran the other thing.
If you run an agent that writes code, you most likely have a list. A list of the commands it may run without asking you.
Underneath that list sits one assumption: that anything dangerous will show up as a question you can refuse. That assumption is the thing that fell.
Why the check saw nothing
Shell built-ins are not programs sitting on disk. The check was looking for programs on disk. So they went through without ever surfacing in front of a human.
Then comes the ordinary part. Git reads a setting that says which program shows its output. Python reads another one. Nobody thinks about these settings, which is precisely the point of the attack. You change them a minute earlier, and after that git branch does whatever you prepared for it.
There is no memory corruption here and no escalated permission. There is a gap between what you approved and what the command now means.
What I take from it
An allowlist gives a comfort it has not earned. It checks names, while the attack works on meaning. As long as you are checking strings, there will always be a way for the string to mean something else.
So the boundary should not sit at the command line. It should sit around the whole process: separate environment, cut network, rights for today's task. Then it stops mattering what the agent decided to run, because there is nowhere for it to go.
And yes, this is Docker advertising their sandboxes. The thought underneath is still right.