Skip to main content

Vendor/product archive

anysphere / cursor CVEs

Beta · best-effort

21 CVEs tagged to anysphere / cursor2 Critical, 15 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2026-50549

Published Jun 25, 2026

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, the agent canonicalizes the targe…

CVSS 9.3 · Critical
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2026-50548

Published Jun 25, 2026

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox grants write access to the comman…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-31854

Published Mar 11, 2026

Cursor is a code editor built for programming with AI. Prior to 2.0 ,if a visited website contains maliciously crafted instructions, the model may attempt to follow them in order…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-26268

Published Feb 13, 2026

Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection)…

CVSS 8.0 · High
evidence mentions
5
Buzz score
37.9
Vendor/product tagsBeta · best-effort

CVE-2026-22708

Published Jan 14, 2026

Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, certain shell built-ins can stil…

CVSS 7.2 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-64110

Published Nov 5, 2025

Cursor is a code editor built for programming with AI. In versions 1.7.23 and below, a logic bug allows a malicious agent to read sensitive files that should be protected via curs…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64108

Published Nov 4, 2025

Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a prompt injection attacker to circumvent sensitive file protec…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64107

Published Nov 4, 2025

Cursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may lead to RCE. Cursor detects path manipulation via forward s…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64106

Published Nov 4, 2025

Cursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor's MCP server installation enables specially crafted deep-li…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59944

Published Oct 3, 2025

Cursor is a code editor built for programming with AI. Versions 1.6.23 and below contain case-sensitive checks in the way Cursor IDE protects its sensitive files (e.g., */.cursor/…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2025-61593

Published Oct 3, 2025

Cursor is a code editor built for programming with AI. In versions 1.7 and below, a vulnerability in the way Cursor CLI Agent protects its sensitive files (i.e. */.cursor/cli.json…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-61592

Published Oct 3, 2025

Cursor is a code editor built for programming with AI. In versions 1.7 and below, automatic loading of project-specific CLI configuration from the current working directory (<proj…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-61591

Published Oct 3, 2025

Cursor is a code editor built for programming with AI. In versions 1.7 and below, when MCP uses OAuth authentication with an untrusted MCP server, an attacker can impersonate a ma…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-61590

Published Oct 3, 2025

Cursor is a code editor built for programming with AI. Versions 1.6 and below are vulnerable to Remote Code Execution (RCE) attacks through Visual Studio Code Workspaces. Workspac…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-61589

Published Oct 3, 2025

Cursor is a code editor built for programming with AI. In versions 1.6 and below, Mermaid (a to render diagrams) allows embedding images which then get rendered by Cursor in the c…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54135

Published Aug 5, 2025

Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions below 1.3.9, If the file is a dotfile, editing it…

CVSS 8.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-54130

Published Aug 5, 2025

Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions less than 1.3.9. If the file is a dotfile, editin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54136

Published Aug 2, 2025

Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and persistent code execution by modifying an already trusted MCP…

CVSS 7.2 · High
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2025-54133

Published Aug 2, 2025

Cursor is a code editor built for programming with AI. In versions 1.17 through 1.2, there is a UI information disclosure vulnerability in Cursor's MCP (Model Context Protocol) de…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54132

Published Aug 1, 2025

Cursor is a code editor built for programming with AI. In versions below 1.3, Mermaid (which is used to render diagrams) allows embedding images which then get rendered by Cursor…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54131

Published Aug 1, 2025

Cursor is a code editor built for programming with AI. In versions below 1.3, an attacker can bypass the allow list in auto-run mode with a backtick (`) or $(cmd). If a user has s…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-21 of 21 CVEsPage 1 of 1