product1 distinct publisher
The allowlist read the command name, not what the command would do
CVE-2026-22708 let injected text rewrite a Cursor agent's environment, so an approved "git branch" ran something else. It worked with an empty allowlist too.
Publishers:docker.com
Reality
- Evidence58
- Adoption45
- Hype gap+18
- Incentives78
- Confidence55