04:31
2026-09-07
dev.to
ai-safety
The Cursor Allowlist Bypass That Starts With a File Named curl
A developer shipped CVE-2026-22708 coverage to secops-toolkit-mcp, a toolkit of defensive SecOps helpers for AI coding agents. The CVE is a Cursor terminal allowlist bypass where a malicious file in a…