Cursor

Anysphere · 22 CVEs

CVE-2026-63093
HIGH

Cursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace

Jul 17, 2026

CVE-2026-50548
CRITICAL

Cursor Desktop sandbox escape via agent-controlled working directory

Jun 25, 2026

CVE-2026-50549
CRITICAL

Cursor Desktop sandbox escape via symlink and failed path canonicalization

Jun 25, 2026

CVE-2026-31854
HIGH

Cursor Affected by Arbitrary Code Execution via Prompt Injection and Whitelist Bypass

Mar 11, 2026

CVE-2026-26268
CRITICAL

Cursor sandbox escape via Git hooks

Feb 13, 2026

CVE-2026-22708
HIGH

Cursor has a Terminal Tool Allowlist Bypass via Environment Variables

Jan 14, 2026

CVE-2025-64110
HIGH

Cursor: Authentication Bypass Possible via New Cursorignore Write

Nov 4, 2025

CVE-2025-64108
HIGH

Cursor's Sensitive File Modification can Lead to NTFS Path Quirks

Nov 4, 2025

CVE-2025-64107
HIGH

Cursor is Vulnerable to Path Manipulation Using Backslashes on Windows

Nov 4, 2025

CVE-2025-64106
HIGH

Cursor: Speedbump Modal Bypass in MCP Server Deep-Link

Nov 4, 2025

CVE-2025-59944
CRITICAL

Cursor IDE: Sensitive File Overwrite Bypass is Possible

Oct 3, 2025

CVE-2025-61593
HIGH

Cursor CLI Agent: Sensitive File Overwrite Bypass

Oct 3, 2025

CVE-2025-61592
HIGH

Cursor CLI: Arbitrary Code Execution Possible through Permissive CLI Config

Oct 3, 2025

CVE-2025-61591
HIGH

Cursor CLI's Cursor Agent MCP OAuth2 Communication is Vulnerable to Remote Code Execution

Oct 3, 2025

CVE-2025-61590
HIGH

Cursor is vulnerable to RCE via .code-workspace files using Prompt Injection

Oct 3, 2025

CVE-2025-61589
MEDIUM

Cursor: Potential Information Leakage via Mermaid Diagram

Oct 3, 2025

CVE-2025-54130
CRITICAL

Cursor Agent is vulnerable prompt injection via Editor Special Files

Aug 5, 2025

CVE-2025-54135
CRITICAL

Cursor Agent is vulnerable to prompt injection via MCP Special Files

Aug 5, 2025

CVE-2025-54136
HIGH

Cursor's Modification of MCP Server Definitions Bypasses Manual Re-approvals

Aug 1, 2025

CVE-2025-54133
MEDIUM

Cursor's MCP Install Deeplink Does Not Show Arguments in its User-Dialog

Aug 1, 2025

CVE-2025-54132
HIGH

Cursor's Mermaid Diagram Tool is Vulnerable to an Arbitrary Image Fetch

Aug 1, 2025

CVE-2025-54131
HIGH

Cursor bypasses its allow list to execute arbitrary commands

Aug 1, 2025

Showing 1 to 22 of 22 CVEs