Cursor
Anysphere · 22 CVEs
Cursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace
Jul 17, 2026
Cursor Desktop sandbox escape via agent-controlled working directory
Jun 25, 2026
Cursor Desktop sandbox escape via symlink and failed path canonicalization
Jun 25, 2026
Cursor Affected by Arbitrary Code Execution via Prompt Injection and Whitelist Bypass
Mar 11, 2026
Cursor sandbox escape via Git hooks
Feb 13, 2026
Cursor has a Terminal Tool Allowlist Bypass via Environment Variables
Jan 14, 2026
Cursor: Authentication Bypass Possible via New Cursorignore Write
Nov 4, 2025
Cursor's Sensitive File Modification can Lead to NTFS Path Quirks
Nov 4, 2025
Cursor is Vulnerable to Path Manipulation Using Backslashes on Windows
Nov 4, 2025
Cursor: Speedbump Modal Bypass in MCP Server Deep-Link
Nov 4, 2025
Cursor IDE: Sensitive File Overwrite Bypass is Possible
Oct 3, 2025
Cursor CLI Agent: Sensitive File Overwrite Bypass
Oct 3, 2025
Cursor CLI: Arbitrary Code Execution Possible through Permissive CLI Config
Oct 3, 2025
Cursor CLI's Cursor Agent MCP OAuth2 Communication is Vulnerable to Remote Code Execution
Oct 3, 2025
Cursor is vulnerable to RCE via .code-workspace files using Prompt Injection
Oct 3, 2025
Cursor: Potential Information Leakage via Mermaid Diagram
Oct 3, 2025
Cursor Agent is vulnerable prompt injection via Editor Special Files
Aug 5, 2025
Cursor Agent is vulnerable to prompt injection via MCP Special Files
Aug 5, 2025
Cursor's Modification of MCP Server Definitions Bypasses Manual Re-approvals
Aug 1, 2025
Cursor's MCP Install Deeplink Does Not Show Arguments in its User-Dialog
Aug 1, 2025
Cursor's Mermaid Diagram Tool is Vulnerable to an Arbitrary Image Fetch
Aug 1, 2025
Cursor bypasses its allow list to execute arbitrary commands
Aug 1, 2025
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-63093 | Cursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace | HIGH | 0.85% | Jul 17, 2026 |
| CVE-2026-50548 | Cursor Desktop sandbox escape via agent-controlled working directory | CRITICAL | 1.01% | Jun 25, 2026 |
| CVE-2026-50549 | Cursor Desktop sandbox escape via symlink and failed path canonicalization | CRITICAL | 1.01% | Jun 25, 2026 |
| CVE-2026-31854 | Cursor Affected by Arbitrary Code Execution via Prompt Injection and Whitelist Bypass | HIGH | 0.45% | Mar 11, 2026 |
| CVE-2026-26268 | Cursor sandbox escape via Git hooks | CRITICAL | 0.43% | Feb 13, 2026 |
| CVE-2026-22708 | Cursor has a Terminal Tool Allowlist Bypass via Environment Variables | HIGH | 0.80% | Jan 14, 2026 |
| CVE-2025-64110 | Cursor: Authentication Bypass Possible via New Cursorignore Write | HIGH | 0.39% | Nov 4, 2025 |
| CVE-2025-64108 | Cursor's Sensitive File Modification can Lead to NTFS Path Quirks | HIGH | 0.48% | Nov 4, 2025 |
| CVE-2025-64107 | Cursor is Vulnerable to Path Manipulation Using Backslashes on Windows | HIGH | 0.38% | Nov 4, 2025 |
| CVE-2025-64106 | Cursor: Speedbump Modal Bypass in MCP Server Deep-Link | HIGH | 0.40% | Nov 4, 2025 |
| CVE-2025-59944 | Cursor IDE: Sensitive File Overwrite Bypass is Possible | CRITICAL | 0.41% | Oct 3, 2025 |
| CVE-2025-61593 | Cursor CLI Agent: Sensitive File Overwrite Bypass | HIGH | 0.41% | Oct 3, 2025 |
| CVE-2025-61592 | Cursor CLI: Arbitrary Code Execution Possible through Permissive CLI Config | HIGH | 0.46% | Oct 3, 2025 |
| CVE-2025-61591 | Cursor CLI's Cursor Agent MCP OAuth2 Communication is Vulnerable to Remote Code Execution | HIGH | 1.16% | Oct 3, 2025 |
| CVE-2025-61590 | Cursor is vulnerable to RCE via .code-workspace files using Prompt Injection | HIGH | 0.52% | Oct 3, 2025 |
| CVE-2025-61589 | Cursor: Potential Information Leakage via Mermaid Diagram | MEDIUM | 0.29% | Oct 3, 2025 |
| CVE-2025-54130 | Cursor Agent is vulnerable prompt injection via Editor Special Files | CRITICAL | 0.30% | Aug 5, 2025 |
| CVE-2025-54135 | Cursor Agent is vulnerable to prompt injection via MCP Special Files | CRITICAL | 1.81% | Aug 5, 2025 |
| CVE-2025-54136 | Cursor's Modification of MCP Server Definitions Bypasses Manual Re-approvals | HIGH | 28.26% | Aug 1, 2025 |
| CVE-2025-54133 | Cursor's MCP Install Deeplink Does Not Show Arguments in its User-Dialog | MEDIUM | 0.37% | Aug 1, 2025 |
| CVE-2025-54132 | Cursor's Mermaid Diagram Tool is Vulnerable to an Arbitrary Image Fetch | HIGH | 0.35% | Aug 1, 2025 |
| CVE-2025-54131 | Cursor bypasses its allow list to execute arbitrary commands | HIGH | 0.48% | Aug 1, 2025 |
Showing 1 to 22 of 22 CVEs