Coding Agent Horror Stories: The Command You Already Approved
On January 14, 2026, Pillar Security disclosed CVE-2026-22708, a high-severity flaw in Cursor that allowed shell built-ins like export, typeset, and declare to execute without appearing in the allowli…