CVE-2026-63093
- EPSS 0.56%
- Veröffentlicht 17.07.2026 14:23:41
- Zuletzt bearbeitet 14.08.2026 14:47:37
Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and opens a craf...
CVE-2026-50548
- EPSS 0.96%
- Veröffentlicht 25.06.2026 18:47:56
- Zuletzt bearbeitet 26.06.2026 16:51:25
Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox grants write access to the command's working directory. A flaw was identified in how the agent could mod...
CVE-2026-50549
- EPSS 1.27%
- Veröffentlicht 25.06.2026 18:47:45
- Zuletzt bearbeitet 26.06.2026 16:51:39
Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, the agent canonicalizes the target path to confirm it stays inside the workspace, but when canonicalizat...
CVE-2026-31854
- EPSS 0.28%
- Veröffentlicht 11.03.2026 17:16:58
- Zuletzt bearbeitet 20.03.2026 16:34:35
Cursor is a code editor built for programming with AI. Prior to 2.0 ,if a visited website contains maliciously crafted instructions, the model may attempt to follow them in order to “assist” the user. When combined with a bypass of the command whitel...
CVE-2026-26268
- EPSS 0.65%
- Veröffentlicht 13.02.2026 16:54:04
- Zuletzt bearbeitet 18.02.2026 17:59:35
Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection) could write to improperly protected .git settings, including git hooks...
CVE-2026-22708
- EPSS 0.56%
- Veröffentlicht 14.01.2026 16:43:54
- Zuletzt bearbeitet 03.02.2026 18:36:39
Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, certain shell built-ins can still be executed without appearing in the allowlist and without requiring ...
CVE-2025-64110
- EPSS 0.36%
- Veröffentlicht 04.11.2025 23:24:46
- Zuletzt bearbeitet 07.11.2025 13:04:09
Cursor is a code editor built for programming with AI. In versions 1.7.23 and below, a logic bug allows a malicious agent to read sensitive files that should be protected via cursorignore. An attacker who has already achieved prompt injection, or a m...
CVE-2025-64108
- EPSS 0.45%
- Veröffentlicht 04.11.2025 22:58:53
- Zuletzt bearbeitet 10.11.2025 18:38:51
Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a prompt injection attacker to circumvent sensitive file protections and overwrite files which Cursor requires human approval to overw...
CVE-2025-64107
- EPSS 0.36%
- Veröffentlicht 04.11.2025 22:51:42
- Zuletzt bearbeitet 10.11.2025 19:54:02
Cursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may lead to RCE. Cursor detects path manipulation via forward slashes (./.cursor/./././././mcp.json etc.), and requires human approval...
CVE-2025-64106
- EPSS 0.37%
- Veröffentlicht 04.11.2025 22:48:14
- Zuletzt bearbeitet 07.11.2025 17:48:28
Cursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor's MCP server installation enables specially crafted deep-links to bypass the standard security warnings and conceal executed comma...