CVEs we hold for Cursor
Records whose assigning authority named Cursor as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-73218Cursor: Sandbox escape via launching privileged containerscursor CVE-2026-73217Cursor: Sandbox escape via tampered Python virtual environmentscursor CVE-2026-50549Cursor Desktop sandbox escape via symlink and failed path canonicalizationcursor CVE-2026-50548Cursor Desktop sandbox escape via agent-controlled working directorycursor CVE-2026-48989Windows-MCP: HTTP transports expose unauthenticated PowerShell control with wildcard CORSCursorTouch Windows-MCP CVE-2026-48124Cursor Desktop sandbox escape via Claude hook configurationcursor CVE-2026-31854Cursor Affected by Arbitrary Code Execution via Prompt Injection and Whitelist Bypasscursor CVE-2026-22708Cursor has a Terminal Tool Allowlist Bypass via Environment Variablescursor CVE-2025-9190TCC Bypass via misconfigured Node fuses in CursorCursor CVE-2025-64110Cursor: Authentication Bypass Possible via New Cursorignore Writecursor CVE-2025-64109Cursor CLI Beta: Command Injection via Untrusted MCP Configurationcursor CVE-2025-64108Cursor's Sensitive File Modification can Lead to NTFS Path Quirkscursor CVE-2025-64107Cursor is Vulnerable to Path Manipulation Using Backslashes on Windowscursor CVE-2025-64106Cursor: Speedbump Modal Bypass in MCP Server Deep-Linkcursor CVE-2025-61592Cursor CLI: Arbitrary Code Execution Possible through Permissive CLI Configcursor CVE-2025-61591Cursor CLI's Cursor Agent MCP OAuth2 Communication is Vulnerable to Remote Code Executioncursor CVE-2025-61590Cursor is vulnerable to RCE via .code-workspace files using Prompt Injectioncursor CVE-2025-61589Cursor: Potential Information Leakage via Mermaid Diagramcursor CVE-2025-59944Cursor IDE: Sensitive File Overwrite Bypass is Possiblecursor CVE-2025-54136Cursor's Modification of MCP Server Definitions Bypasses Manual Re-approvalscursor CVE-2025-54135Cursor Agent is vulnerable to prompt injection via MCP Special Filescursor CVE-2025-54133Cursor's MCP Install Deeplink Does Not Show Arguments in its User-Dialogcursor CVE-2025-54132Cursor's Mermaid Diagram Tool is Vulnerable to an Arbitrary Image Fetchcursor CVE-2025-54131Cursor bypasses its allow list to execute arbitrary commandscursor CVE-2025-54130Cursor Agent is vulnerable prompt injection via Editor Special Filescursor CVE-2010-20045FileWrangler <= 5.30 Stack Buffer OverflowCursorArts FileWrangler 30 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.