Evidence record / cursor
A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.
2026-09-21-cursor-no-in-window-security-advisory-despite-a-public-sandbox-escape-claim
No in-window security advisory, despite a public sandbox-escape claim. Nothing on the advisory channel. Lane C holds a 2026-09-15 researcher post (https://x.com/matviy/status/2099872739758874805) claiming a Cursor CLI macOS sandbox escape via a git core.fsmonitor variant after an earlier fix, with vendor acknowledgement. No primary surface confirms or dates a fix.
Channel: docs-only (negative result). Half: defect. Date: window.
Operator consequence: Watch: an advisory on cursor/cursor or a CLI changelog line naming git or fsmonitor settles it. Until then, treat the CLI sandbox on macOS as not covering git invoked by the harness, and do not run the CLI against untrusted repos on the strength of the sandbox alone. This is the same bug class as Copilot CLI’s GHSA-9ccr-r5hg-74gf (patched there in 1.0.43).
Receipt
Finding metadata
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Finding ID: 2026-09-21-cursor-no-in-window-security-advisory-despite-a-public-sandbox-escape-claim
Profile citations
- cursor / claim / no-advisory-sandbox-claim
Source links
Primary links, including exact changelog lines when available.
Versioned source: run artifact