VYPR
High severity8.8NVD Advisory· Published Mar 11, 2026· Updated Jun 17, 2026

CVE-2026-31854

CVE-2026-31854

Description

Cursor is a code editor built for programming with AI. Prior to 2.0 ,if a visited website contains maliciously crafted instructions, the model may attempt to follow them in order to “assist” the user. When combined with a bypass of the command whitelist mechanism, such indirect prompt injections could result in commands being executed automatically, without the user’s explicit intent, thereby posing a significant security risk. This vulnerability is fixed in 2.0.

Affected products

3
  • Getcursor/Cursorllm-create2 versions
    <2.0+ 1 more
    • (no CPE)range: <2.0
    • (no CPE)range: < 2.0
  • cpe:2.3:a:anysphere:cursor:*:*:*:*:*:*:*:*
    Range: <2.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.