VendorsAnyspherecursorany version
Vulnerabilities

Anysphere Cursor any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

22CVEs
CVE-2026-26268
Cursor sandbox escape via Git hooks
Published 2026-02-13 · Analyzed
9.9EPSS 0.004
CVE-2025-54135
Cursor Agent is vulnerable to prompt injection via MCP Special Files
Published 2025-08-05 · Analyzed
9.8EPSS 0.018
CVE-2026-50549
Cursor Desktop sandbox escape via symlink and failed path canonicalization
Published 2026-06-25 · Analyzed
9.8EPSS 0.010
CVE-2026-50548
Cursor Desktop sandbox escape via agent-controlled working directory
Published 2026-06-25 · Analyzed
9.8EPSS 0.010
CVE-2026-22708
Cursor has a Terminal Tool Allowlist Bypass via Environment Variables
Published 2026-01-14 · Analyzed
9.8EPSS 0.008
CVE-2025-59944
Cursor IDE: Sensitive File Overwrite Bypass is Possible
Published 2025-10-03 · Analyzed
9.8EPSS 0.004
CVE-2025-54130
Cursor Agent is vulnerable prompt injection via Editor Special Files
Published 2025-08-05 · Analyzed
9.8EPSS 0.003
CVE-2025-54133
Cursor's MCP Install Deeplink Does Not Show Arguments in its User-Dialog
Published 2025-08-01 · Analyzed
9.6EPSS 0.004
CVE-2025-54136
Cursor's Modification of MCP Server Definitions Bypasses Manual Re-approvals
Published 2025-08-01 · Analyzed
8.8EPSS 0.263
CVE-2025-61591
Cursor CLI's Cursor Agent MCP OAuth2 Communication is Vulnerable to Remote Code Execution
Published 2025-10-03 · Analyzed
8.8EPSS 0.012
CVE-2026-63093
Cursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace
Published 2026-07-17 · Analyzed
8.8EPSS 0.008
CVE-2025-54131
Cursor bypasses its allow list to execute arbitrary commands
Published 2025-08-01 · Analyzed
8.8EPSS 0.005
CVE-2025-61592
Cursor CLI: Arbitrary Code Execution Possible through Permissive CLI Config
Published 2025-10-03 · Analyzed
8.8EPSS 0.005
CVE-2026-31854
Cursor Affected by Arbitrary Code Execution via Prompt Injection and Whitelist Bypass
Published 2026-03-11 · Analyzed
8.8EPSS 0.005
CVE-2025-64108
Cursor's Sensitive File Modification can Lead to NTFS Path Quirks
Published 2025-11-04 · Analyzed
8.8EPSS 0.005
CVE-2025-61593
Cursor CLI Agent: Sensitive File Overwrite Bypass
Published 2025-10-03 · Analyzed
8.8EPSS 0.004
CVE-2025-64106
Cursor: Speedbump Modal Bypass in MCP Server Deep-Link
Published 2025-11-04 · Analyzed
8.8EPSS 0.004
CVE-2025-64107
Cursor is Vulnerable to Path Manipulation Using Backslashes on Windows
Published 2025-11-04 · Analyzed
8.8EPSS 0.004
CVE-2025-64110
Cursor: Authentication Bypass Possible via New Cursorignore Write
Published 2025-11-04 · Analyzed
8.7EPSS 0.004
CVE-2025-61590
Cursor is vulnerable to RCE via .code-workspace files using Prompt Injection
Published 2025-10-03 · Analyzed
7.5EPSS 0.005
CVE-2025-54132
Cursor's Mermaid Diagram Tool is Vulnerable to an Arbitrary Image Fetch
Published 2025-08-01 · Analyzed
7.5EPSS 0.004
CVE-2025-61589
Cursor: Potential Information Leakage via Mermaid Diagram
Published 2025-10-03 · Analyzed
5.9EPSS 0.003