|
Linux terminal sandbox always fails preflight on RHEL 9 / Rocky 9: bubblewrap cannot bind-mount onto the symlinked CA bundle
|
|
2
|
90
|
August 10, 2026
|
|
Soft soft soft loop freeze
|
|
1
|
23
|
August 10, 2026
|
|
Orphaned agent-exec gh shell storm maxes CPU after Plan Mode (multi-root)
|
|
9
|
133
|
August 10, 2026
|
|
Critical: Terminal Sandbox fails on OrbStack VMs, breaking Agent and Remote SSH workflow
|
|
11
|
81
|
August 8, 2026
|
|
Agent sandbox redirects PLAYWRIGHT_BROWSERS_PATH and npm_config_devdir to empty cursor-sandbox-cache (Windows) — Playwright reinstall loops + npm 11 warnings
|
|
1
|
26
|
August 6, 2026
|
|
Cursor agents should be restricted from access of files outside the project without permission
|
|
6
|
900
|
August 6, 2026
|
|
Sandboxed shell commands return no exit status
|
|
1
|
20
|
August 5, 2026
|
|
Terminal sandbox is incorrectly reported as unsupported on OrbStack Linux kernel 7.0.x (AppArmor suggestion is misleading)
|
|
3
|
30
|
August 5, 2026
|
|
Serious Boundary Issue bypass
|
|
8
|
91
|
August 5, 2026
|
|
Agent sandbox sets system proxy to 127.0.0.1:57126 and breaks all other apps
|
|
1
|
29
|
August 4, 2026
|
|
Agent Write permission denied on .cs files + NTFS Length +1024
|
|
1
|
24
|
August 3, 2026
|
|
Git Graph + Agent: multi-root workspace uses first folder only
|
|
5
|
99
|
July 30, 2026
|
|
Agent Shell hangs/crashes on NFS workspaces due to hardcoded sandbox glob patterns
|
|
1
|
36
|
July 23, 2026
|
|
Rg/grep issue in sandbox
|
|
3
|
94
|
July 22, 2026
|
|
Shell/terminal sandbox fails to start on WSL2 — Failed to mount ".git/hooks" read-only: No such file or directory
|
|
3
|
66
|
July 21, 2026
|
|
Sandbox processes persist after Cursor exit and cannot be killed by user
|
|
9
|
294
|
July 20, 2026
|
|
Cursor can only access Terminal with legacy terminal tool on
|
|
12
|
217
|
July 16, 2026
|
|
Permissions.json allowlists disable Auto-review (with Sandbox) — contradicts docs
|
|
1
|
109
|
July 15, 2026
|
|
Sandbox .cursorignore bypass: tracked ignored files readable via git object store
|
|
2
|
46
|
July 15, 2026
|
|
Possible stale Cursor sandbox state after CLI exit contributed to deletion of a workspace used by OMP
|
|
2
|
48
|
July 10, 2026
|
|
.cursorignore sandbox behavior seems to depend on workspace being a Git repository
|
|
2
|
52
|
July 9, 2026
|
|
.cursorignore sandbox exclusions may fail with very large ignored file trees
|
|
2
|
43
|
July 9, 2026
|
|
Ask Mode ignores Auto-Run Allowlist approval for shell commands and runs them sandboxed
|
|
7
|
187
|
July 8, 2026
|
|
Sandbox in Dev Container: writes inside workspace fail with Permission denied
|
|
2
|
68
|
July 6, 2026
|
|
Auto-review Run Mode
|
|
14
|
2127
|
July 5, 2026
|
|
Auto-review, sandbox and the Docker
|
|
1
|
94
|
July 5, 2026
|
|
After context summarization, the agent loses active Skills and tool-usage knowledge (causes disruptive tool/permission failures)
|
|
2
|
59
|
July 2, 2026
|
|
Sandboxed shell commands intermittently hang indefinitely (stuck in request_wait_answer), persists across container restart
|
|
2
|
51
|
July 1, 2026
|
|
Critical Governance Issue: cursor_sandbox and Seccomp blocking Root/Sudo kill signals (EACCES)
|
|
9
|
307
|
June 30, 2026
|
|
Will not get past Switching Workspace Root
|
|
0
|
47
|
June 29, 2026
|