CVE-2026-26268
- EPSS 0.04%
- Veröffentlicht 13.02.2026 16:54:04
- Zuletzt bearbeitet 18.02.2026 17:59:35
Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection) could write to improperly protected .git settings, including git hooks...
CVE-2026-22708
- EPSS 0.07%
- Veröffentlicht 14.01.2026 16:43:54
- Zuletzt bearbeitet 03.02.2026 18:36:39
Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, certain shell built-ins can still be executed without appearing in the allowlist and without requiring ...
CVE-2025-64110
- EPSS 0.05%
- Veröffentlicht 04.11.2025 23:24:46
- Zuletzt bearbeitet 07.11.2025 13:04:09
Cursor is a code editor built for programming with AI. In versions 1.7.23 and below, a logic bug allows a malicious agent to read sensitive files that should be protected via cursorignore. An attacker who has already achieved prompt injection, or a m...
CVE-2025-64108
- EPSS 0.1%
- Veröffentlicht 04.11.2025 22:58:53
- Zuletzt bearbeitet 10.11.2025 18:38:51
Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a prompt injection attacker to circumvent sensitive file protections and overwrite files which Cursor requires human approval to overw...
CVE-2025-64107
- EPSS 0.07%
- Veröffentlicht 04.11.2025 22:51:42
- Zuletzt bearbeitet 10.11.2025 19:54:02
Cursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may lead to RCE. Cursor detects path manipulation via forward slashes (./.cursor/./././././mcp.json etc.), and requires human approval...
CVE-2025-64106
- EPSS 0.07%
- Veröffentlicht 04.11.2025 22:48:14
- Zuletzt bearbeitet 07.11.2025 17:48:28
Cursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor's MCP server installation enables specially crafted deep-links to bypass the standard security warnings and conceal executed comma...
CVE-2025-59944
- EPSS 0.12%
- Veröffentlicht 03.10.2025 20:15:30
- Zuletzt bearbeitet 16.10.2025 18:16:19
Cursor is a code editor built for programming with AI. Versions 1.6.23 and below contain case-sensitive checks in the way Cursor IDE protects its sensitive files (e.g., */.cursor/mcp.json), which allows attackers to modify the content of these files ...
CVE-2025-61593
- EPSS 0.1%
- Veröffentlicht 03.10.2025 17:28:03
- Zuletzt bearbeitet 09.10.2025 17:30:22
Cursor is a code editor built for programming with AI. In versions 1.7 and below, a vulnerability in the way Cursor CLI Agent protects its sensitive files (i.e. */.cursor/cli.json) allows attackers to modify the content of the files through prompt in...
CVE-2025-61592
- EPSS 0.15%
- Veröffentlicht 03.10.2025 17:23:37
- Zuletzt bearbeitet 09.10.2025 17:23:11
Cursor is a code editor built for programming with AI. In versions 1.7 and below, automatic loading of project-specific CLI configuration from the current working directory (<project>/.cursor/cli.json) could override certain global configurations in ...
CVE-2025-61591
- EPSS 0.09%
- Veröffentlicht 03.10.2025 16:44:54
- Zuletzt bearbeitet 17.10.2025 17:25:27
Cursor is a code editor built for programming with AI. In versions 1.7 and below, when MCP uses OAuth authentication with an untrusted MCP server, an attacker can impersonate a malicious MCP server and return crafted, maliciously injected commands du...