Beltdown2 - Cursor CLI Sandbox Bypassed by Unsandboxed Harness Git
- Beltdown2, published 12 September 2026 by Or Hiltch (Accomplish), shows the Cursor CLI macOS Seatbelt sandbox wrapping the shell tool (
cursorsandbox) while the harness's owngitruns unsandboxed. - A repo
.git/configcore.fsmonitorhelper executes on ordinary status / ls-files during a read-only prompt - no model shell command required, no permission prompt in force/yolo modes. - Same class as Claude Code Beltdown and the broader GitSpawn malicious-git-config campaign; Cursor initially had no universal git hardening on those spawns.
- Fix: Cursor CLI
2026.08.04-aaa8809applies universal **GIT_CONFIG_*env hardening (core.fsmonitor=false,hooksPath=/dev/null, and related) on every git spawn - verified by the researchers. No CVE ID** in the public write-up. - Fleet action: upgrade Cursor CLI builds, treat untrusted archives with pre-armed
.git/as hostile, and inventory coding-agent versions before trusting sandbox marketing.
On 12 September 2026, Or Hiltch at Accomplish published Beltdown2: the Cursor CLI macOS sandbox did not cover the path that mattered. Seatbelt via cursorsandbox wrapped the shell tool. The harness's own git - used for status, ls-files, and context - ran outside the sandbox and honored a malicious .git/config core.fsmonitor. A read-only prompt was enough.
Seatbelt around the wrong process
Cursor's CLI advertises a workspace-scoped Seatbelt profile that denies $HOME and network for sandboxed shell. Beltdown2's process ancestry showed the opposite for git: cursor-agent → git ls-files → fsmonitor helper, with CURSOR_SANDBOX unset and $HOME` writable. The model never asked for a shell command. Context gather did.
That is the same hinge as Claude Code Beltdown and the multi-agent GitSpawn findings: repository-local Git config is an execution path. Beltdown2's differentiator for Cursor was the complete absence of hardening on observed git spawns at the time of testing (July 2026 builds), versus Claude Code's partial -c core.fsmonitor=false coverage that still missed paths. Adjacent Cursor sandbox history - DuneSlide and Git-hooks sandbox escape CVE-2026-26268 - already taught teams not to equate "sandbox on" with "every child confined."
The fix that closed the coordination bug
Cursor CLI 2026.08.04-aaa8809 shipped **universal GIT_CONFIG_* environment hardening on every git spawn: core.fsmonitor=false, hooksPath=/dev/null, attributesFile=/dev/null, and related safe defaults. Environment-scoped config outranks the repository's .git/config, so individual call sites cannot forget a flag. Accomplish verified the helper no longer fires. There is no CVE ID in the public post - track the build string**, not a scanner CVE hit.
- Upgrade Cursor CLI to 2026.08.04-aaa8809 or later across the fleet.
- Treat zip/shared folders with pre-armed
.git/as hostile delivery - the Beltdown2 PoC did not need a live clone. - Do not rely on force/yolo + sandbox as a substitute for git hardening; Beltdown2 escaped without a shell approval.
- Compare agent sandbox designs: per-tool Seatbelt versus whole-process/VM confinement (as discussed in Codex and Antigravity comparisons in Claude Code vs Codex vs Cursor permission models).
- Inventory coding-agent versions the same way you inventory browsers - sandbox marketing is not a CMDB.
For how Codex frames sandbox and approvals, see the OpenAI Codex sandbox and approval model. Beltdown2 is the Cursor-shaped reminder that harness git is in the trust boundary whether or not the UI labels it a tool.
How Anomity inventories and governs the escape class
Anomity's Endpoint Sensor inventories agents and CLIs among the eight AI artifact types, so Cursor CLI builds that predate 2026.08.04-aaa8809 are a fleet query. On agents with hooks such as Claude Code PreToolUse, runtime governance returns allow, deny, or log before risky shell or git-adjacent tool paths run. Decisions land in a 90-day audit trail to SIEM, Slack, email, or Jira. Metadata only; secrets redacted on-endpoint. SOC 2 Type II; complements Network, EDR, DLP, and GRC.
Sandboxes that wrap only the shell tool leave harness git as an exit door. Upgrade the CLI, inventory the fleet, and book a 30-minute demo to see which coding-agent builds still predate the hardening.
Frequently asked questions
What is Beltdown2?
Beltdown2 is Accomplish's name for a Cursor CLI sandbox escape disclosed publicly on 12 September 2026. macOS Seatbelt confined model-driven shell commands, but the harness spawned git outside that profile. Repository core.fsmonitor then ran attacker code with the user's full authority during routine context gather.
How is this different from GitSpawn?
GitSpawn (Manifold, 1 September 2026) is the multi-agent campaign framing for malicious .git/config helpers across coding agents. Beltdown2 zooms into the Cursor CLI trust boundary: Seatbelt versus unsandboxed harness git, with a concrete fix build (2026.08.04-aaa8809) and no CVE identifier in the source write-up. Use GitSpawn for fleet patch matrices; use Beltdown2 when the question is whether Cursor's sandbox actually covered git.
Was there a CVE?
The Accomplish write-up does not assign a CVE. Defenders should track the Cursor CLI build string 2026.08.04-aaa8809 (and later) rather than waiting for a CVE match. Adjacent Cursor sandbox issues such as DuneSlide and Git-hooks escapes carry their own identifiers.
What fixed it?
Cursor applied universal GIT_CONFIG environment overrides on every harness git spawn so repository config cannot re-enable fsmonitor or hooks. That is stronger than hoping every call site remembers -c core.fsmonitor=false. Researchers verified the hook no longer fires on the fixed build.
How does Anomity help?
Anomity inventories coding agents and CLIs on managed endpoints so you can find Cursor CLI builds that predate the hardening. Runtime governance can deny risky shell and git-adjacent tool paths at the agent hook, with a 90-day audit trail. Metadata only; secrets redacted on-endpoint. Complements Network, EDR, DLP, and GRC.




