I can see the issue. The first command runs without permission even though the allow list is empty. This might be related to a known bug that was fixed before, but it looks like it may be back.
Could you please share:
What is your Auto-Run Mode setting? (Cursor Settings > Agents > Auto-Run)
Which exact command runs without permission?
Can you check if Legacy Terminal Tool is enabled? (Settings > search “legacy terminal”)
If you can reproduce it, please share the Request ID (chat context menu > Copy Request ID)
This will help us figure out if this is a regression or a new issue.
(havent changed anything in past few weeks)
2. cd, git, php, anything really
3.
(always had this disabled)
4. request id: 956e3e55-33e8-415e-85c2-389d31ca06f4
It looks like a regression related to bypassing the allow list for the first command. Similar bugs were fixed before, but it seems the issue is back in version 2.3.20.
Unfortunately, with Privacy Mode enabled, the logs aren’t available, which makes debugging harder. If you can, please temporarily turn off Privacy Mode (Cursor Settings > Privacy > Privacy Mode), reproduce the issue, then share the new Request ID. That’ll help the team find the cause.