---
title: "Beltdown2 - Cursor CLI Sandbox Bypassed by Unsandboxed Harness Git | Anomity Blog"
description: "Beltdown2 (Accomplish / Or Hiltch, Sep 12 2026): Cursor CLI Seatbelt wraps shell, but unsandboxed harness git honors .git/config core.fsmonitor - fixed in CLI 2026.08.04-aaa8809."
url: "https://anomity.ai/blog/beltdown2-cursor-cli-sandbox-git-fsmonitor-escape/"
source: html
---

On this page

- Seatbelt around the wrong process
- The fix that closed the coordination bug
- How Anomity inventories and governs the escape class
- Frequently asked questions

[← Back to blog](https://anomity.ai/blog/)

- Home

- Blog

- Beltdown2 - Cursor CLI Sandbox Bypassed by Unsandboxed Harness Git

![Anomity robot illustrating Beltdown2 - Cursor CLI Sandbox Bypassed by Unsandboxed Harness Git]

Insights

# Beltdown2 - Cursor CLI Sandbox Bypassed by Unsandboxed Harness Git

Anomity Research
Anomity Research
·
Sep 21, 2026
·
2 min read

Share: Copied

TL;DR

- Beltdown2 , published 12 September 2026 by Or Hiltch (Accomplish), shows the Cursor CLI macOS Seatbelt sandbox wrapping the shell tool ( cursorsandbox ) while the harness's own git runs unsandboxed .
- A repo .git/config core.fsmonitor helper executes on ordinary status / ls-files during a read-only prompt - no model shell command required, no permission prompt in force/yolo modes.
- Same class as Claude Code Beltdown and the broader GitSpawn malicious-git-config campaign; Cursor initially had no universal git hardening on those spawns.
- Fix: Cursor CLI 2026.08.04-aaa8809 applies universal ** GIT_CONFIG_* env hardening ( core.fsmonitor=false , hooksPath=/dev/null , and related) on every git spawn - verified by the researchers. No CVE ID** in the public write-up.
- Fleet action: upgrade Cursor CLI builds, treat untrusted archives with pre-armed .git/ as hostile, and inventory coding-agent versions before trusting sandbox marketing.

On **12 September 2026**, **Or Hiltch** at **Accomplish** published **Beltdown2**: the **Cursor CLI** macOS sandbox did not cover the path that mattered. **Seatbelt** via **cursorsandbox** wrapped the shell tool. The harness's own **git** - used for status, ls-files, and context - ran **outside** the sandbox and honored a malicious **.git/config core.fsmonitor**. A read-only prompt was enough.

## Seatbelt around the wrong process

Cursor's CLI advertises a workspace-scoped Seatbelt profile that denies `$HOME` and network for sandboxed shell. Beltdown2's process ancestry showed the opposite for git: **cursor-agent → git ls-files → fsmonitor helper**, with **CURSOR_SANDBOX unset** and $HOME` writable. The model never asked for a shell command. Context gather did.

That is the same hinge as Claude Code **Beltdown** and the multi-agent **GitSpawn** findings: **repository-local Git config is an execution path**. Beltdown2's differentiator for Cursor was the **complete absence of hardening** on observed git spawns at the time of testing (July 2026 builds), versus Claude Code's partial `-c core.fsmonitor=false` coverage that still missed paths. Adjacent Cursor sandbox history - [DuneSlide](https://anomity.ai/blog/duneslide-cursor-sandbox-escape-cve-2026-50548-50549/) and [Git-hooks sandbox escape CVE-2026-26268](https://anomity.ai/blog/cursor-git-hooks-sandbox-escape-rce-cve-2026-26268/) - already taught teams not to equate "sandbox on" with "every child confined."

## The fix that closed the coordination bug

Cursor CLI **2026.08.04-aaa8809** shipped **universal `GIT_CONFIG_*` environment hardening**on every git spawn: core.fsmonitor=false , hooksPath=/dev/null , attributesFile=/dev/null , and related safe defaults. Environment-scoped config outranks the repository's .git/config , so individual call sites cannot forget a flag. Accomplish verified the helper no longer fires. There is**no CVE ID**in the public post - track the**build string**, not a scanner CVE hit.

- Upgrade Cursor CLI to 2026.08.04-aaa8809 or later across the fleet.
- Treat zip/shared folders with pre-armed .git/ as hostile delivery - the Beltdown2 PoC did not need a live clone.
- Do not rely on force/yolo + sandbox as a substitute for git hardening; Beltdown2 escaped without a shell approval.
- Compare agent sandbox designs : per-tool Seatbelt versus whole-process/VM confinement (as discussed in Codex and Antigravity comparisons in Claude Code vs Codex vs Cursor permission models ).
- Inventory coding-agent versions the same way you inventory browsers - sandbox marketing is not a CMDB.

For how Codex frames sandbox and approvals, see the [OpenAI Codex sandbox and approval model](https://anomity.ai/blog/openai-codex-sandbox-and-approval-model/). Beltdown2 is the Cursor-shaped reminder that **harness git is in the trust boundary** whether or not the UI labels it a tool.

## How Anomity inventories and governs the escape class

Anomity's **Endpoint Sensor** inventories **agents and CLIs** among the eight AI artifact types, so Cursor CLI builds that predate **2026.08.04-aaa8809** are a fleet query. On agents with hooks such as Claude Code **PreToolUse**, [runtime governance](https://anomity.ai/#runtime-governance) returns **allow, deny, or log** before risky shell or git-adjacent tool paths run. Decisions land in a [90-day audit trail](https://anomity.ai/#outcomes) to SIEM, Slack, email, or Jira. Metadata only; secrets redacted on-endpoint. SOC 2 Type II; complements Network, EDR, DLP, and GRC.

Sandboxes that wrap only the shell tool leave harness git as an exit door. Upgrade the CLI, inventory the fleet, and [book a 30-minute demo](https://anomity.ai/#early-access) to see which coding-agent builds still predate the hardening.

Share: Copied

## Frequently asked questions

What is Beltdown2?
Beltdown2 is Accomplish's name for a Cursor CLI sandbox escape disclosed publicly on 12 September 2026. macOS Seatbelt confined model-driven shell commands, but the harness spawned git outside that profile. Repository core.fsmonitor then ran attacker code with the user's full authority during routine context gather.

How is this different from GitSpawn?
GitSpawn (Manifold, 1 September 2026) is the multi-agent campaign framing for malicious .git/config helpers across coding agents. Beltdown2 zooms into the Cursor CLI trust boundary: Seatbelt versus unsandboxed harness git, with a concrete fix build (2026.08.04-aaa8809) and no CVE identifier in the source write-up. Use GitSpawn for fleet patch matrices; use Beltdown2 when the question is whether Cursor's sandbox actually covered git.

Was there a CVE?
The Accomplish write-up does not assign a CVE. Defenders should track the Cursor CLI build string 2026.08.04-aaa8809 (and later) rather than waiting for a CVE match. Adjacent Cursor sandbox issues such as DuneSlide and Git-hooks escapes carry their own identifiers.

What fixed it?
Cursor applied universal GIT_CONFIG environment overrides on every harness git spawn so repository config cannot re-enable fsmonitor or hooks. That is stronger than hoping every call site remembers -c core.fsmonitor=false. Researchers verified the hook no longer fires on the fixed build.

How does Anomity help?
Anomity inventories coding agents and CLIs on managed endpoints so you can find Cursor CLI builds that predate the hardening. Runtime governance can deny risky shell and git-adjacent tool paths at the agent hook, with a 90-day audit trail. Metadata only; secrets redacted on-endpoint. Complements Network, EDR, DLP, and GRC.

## Related

[Insights ### Claude Fable 5.1 and Mythos 5.1: One Model, Two Safeguard Tiers, and a Fallback Your Security Team Will Hit Fable 5.1 and Mythos 5.1 are one model with two safeguard tiers. Flagged cyber requests in Claude Code fall back to Opus 4.8. What it means for you. Anomity Research · Oct 2, 2026 · 5 min](https://anomity.ai/blog/claude-fable-5-1-mythos-5-1-model-fallback-governance/)

[Insights ### NVIDIA's Open Agent Safety Platform Puts Controls Outside the Agent. Now Count the Agents Outside It. OpenShell sandboxes agents with policy outside their reach, and Sentry watches from the DPU. Both cover the agents you enroll. The rest need a list first. Anomity Research · Oct 2, 2026 · 6 min](https://anomity.ai/blog/nvidia-open-agent-safety-platform-openshell-sentry/)

[Insights ### OpenAI Astra Crossed the Critical Cyber Threshold. Its Safeguards Stop at the Model. Astra is OpenAI's first model rated Critical for cyber. OpenAI built safeguards for the model. The agents running it on your endpoints are still yours. Anomity Research · Oct 2, 2026 · 5 min](https://anomity.ai/blog/openai-astra-critical-cyber-capability-enterprise/)

## Structured data

```json
{
  "@context": "https://schema.org",
  "@type": "BlogPosting",
  "headline": "Beltdown2 - Cursor CLI Sandbox Bypassed by Unsandboxed Harness Git",
  "description": "Beltdown2 (Accomplish / Or Hiltch, Sep 12 2026): Cursor CLI Seatbelt wraps shell, but unsandboxed harness git honors .git/config core.fsmonitor - fixed in CLI 2026.08.04-aaa8809.",
  "datePublished": "2026-09-21",
  "dateModified": "2026-09-21",
  "author": {
    "@type": "Person",
    "name": "Anomity Research",
    "jobTitle": "Anomity Research"
  },
  "publisher": {
    "@type": "Organization",
    "name": "Anomity",
    "url": "https://anomity.ai/",
    "sameAs": [
      "https://www.linkedin.com/company/anomity",
      "https://github.com/Anomity-ai",
      "https://www.wikidata.org/wiki/Q140763940"
    ],
    "logo": {
      "@type": "ImageObject",
      "url": "https://anomity.ai/icon-512.png"
    }
  },
  "mainEntityOfPage": {
    "@type": "WebPage",
    "@id": "https://anomity.ai/blog/beltdown2-cursor-cli-sandbox-git-fsmonitor-escape/"
  },
  "image": {
    "@type": "ImageObject",
    "url": "https://anomity.ai/assets/blog/covers/coding-agents.jpg",
    "width": 1200,
    "height": 630
  },
  "articleSection": "Insights",
  "url": "https://anomity.ai/blog/beltdown2-cursor-cli-sandbox-git-fsmonitor-escape/"
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "What is Beltdown2?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Beltdown2 is Accomplish's name for a Cursor CLI sandbox escape disclosed publicly on 12 September 2026. macOS Seatbelt confined model-driven shell commands, but the harness spawned git outside that profile. Repository core.fsmonitor then ran attacker code with the user's full authority during routine context gather."
      }
    },
    {
      "@type": "Question",
      "name": "How is this different from GitSpawn?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "GitSpawn (Manifold, 1 September 2026) is the multi-agent campaign framing for malicious .git/config helpers across coding agents. Beltdown2 zooms into the Cursor CLI trust boundary: Seatbelt versus unsandboxed harness git, with a concrete fix build (2026.08.04-aaa8809) and no CVE identifier in the source write-up. Use GitSpawn for fleet patch matrices; use Beltdown2 when the question is whether Cursor's sandbox actually covered git."
      }
    },
    {
      "@type": "Question",
      "name": "Was there a CVE?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "The Accomplish write-up does not assign a CVE. Defenders should track the Cursor CLI build string 2026.08.04-aaa8809 (and later) rather than waiting for a CVE match. Adjacent Cursor sandbox issues such as DuneSlide and Git-hooks escapes carry their own identifiers."
      }
    },
    {
      "@type": "Question",
      "name": "What fixed it?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Cursor applied universal GIT_CONFIG environment overrides on every harness git spawn so repository config cannot re-enable fsmonitor or hooks. That is stronger than hoping every call site remembers -c core.fsmonitor=false. Researchers verified the hook no longer fires on the fixed build."
      }
    },
    {
      "@type": "Question",
      "name": "How does Anomity help?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Anomity inventories coding agents and CLIs on managed endpoints so you can find Cursor CLI builds that predate the hardening. Runtime governance can deny risky shell and git-adjacent tool paths at the agent hook, with a 90-day audit trail. Metadata only; secrets redacted on-endpoint. Complements Network, EDR, DLP, and GRC."
      }
    }
  ]
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "BreadcrumbList",
  "itemListElement": [
    {
      "@type": "ListItem",
      "position": 1,
      "name": "Home",
      "item": "https://anomity.ai/"
    },
    {
      "@type": "ListItem",
      "position": 2,
      "name": "Blog",
      "item": "https://anomity.ai/blog/"
    },
    {
      "@type": "ListItem",
      "position": 3,
      "name": "Beltdown2 - Cursor CLI Sandbox Bypassed by Unsandboxed Harness Git",
      "item": "https://anomity.ai/blog/beltdown2-cursor-cli-sandbox-git-fsmonitor-escape/"
    }
  ]
}
```
