Anysphere

Cursor

22 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.56%
  • Veröffentlicht 17.07.2026 14:23:41
  • Zuletzt bearbeitet 14.08.2026 14:47:37

Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and opens a craf...

Medienbericht
  • EPSS 0.96%
  • Veröffentlicht 25.06.2026 18:47:56
  • Zuletzt bearbeitet 26.06.2026 16:51:25

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox grants write access to the command's working directory. A flaw was identified in how the agent could mod...

Medienbericht
  • EPSS 1.27%
  • Veröffentlicht 25.06.2026 18:47:45
  • Zuletzt bearbeitet 26.06.2026 16:51:39

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, the agent canonicalizes the target path to confirm it stays inside the workspace, but when canonicalizat...

  • EPSS 0.28%
  • Veröffentlicht 11.03.2026 17:16:58
  • Zuletzt bearbeitet 20.03.2026 16:34:35

Cursor is a code editor built for programming with AI. Prior to 2.0 ,if a visited website contains maliciously crafted instructions, the model may attempt to follow them in order to “assist” the user. When combined with a bypass of the command whitel...

Medienbericht
  • EPSS 0.65%
  • Veröffentlicht 13.02.2026 16:54:04
  • Zuletzt bearbeitet 18.02.2026 17:59:35

Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection) could write to improperly protected .git settings, including git hooks...

  • EPSS 0.56%
  • Veröffentlicht 14.01.2026 16:43:54
  • Zuletzt bearbeitet 03.02.2026 18:36:39

Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, certain shell built-ins can still be executed without appearing in the allowlist and without requiring ...

  • EPSS 0.36%
  • Veröffentlicht 04.11.2025 23:24:46
  • Zuletzt bearbeitet 07.11.2025 13:04:09

Cursor is a code editor built for programming with AI. In versions 1.7.23 and below, a logic bug allows a malicious agent to read sensitive files that should be protected via cursorignore. An attacker who has already achieved prompt injection, or a m...

  • EPSS 0.45%
  • Veröffentlicht 04.11.2025 22:58:53
  • Zuletzt bearbeitet 10.11.2025 18:38:51

Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a prompt injection attacker to circumvent sensitive file protections and overwrite files which Cursor requires human approval to overw...

  • EPSS 0.36%
  • Veröffentlicht 04.11.2025 22:51:42
  • Zuletzt bearbeitet 10.11.2025 19:54:02

Cursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may lead to RCE. Cursor detects path manipulation via forward slashes (./.cursor/./././././mcp.json etc.), and requires human approval...

  • EPSS 0.37%
  • Veröffentlicht 04.11.2025 22:48:14
  • Zuletzt bearbeitet 07.11.2025 17:48:28

Cursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor's MCP server installation enables specially crafted deep-links to bypass the standard security warnings and conceal executed comma...