VYPR

Cursor

by Getcursor

Source repositories

CVEs (32)

  • CVE-2025-54130HigAug 5, 2025
    risk 0.49cvss 7.5epss 0.00

    Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions less than 1.3.9. If the file is a dotfile, editing it requires approval but creating a new one doesn't. Hence, if sensitive editor files, such as the…

  • CVE-2025-54136HigAug 2, 2025
    risk 0.47cvss 7.2epss 0.26

    Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and persistent code execution by modifying an already trusted MCP configuration file inside a shared GitHub repository or editing the file locally on the target's…

  • CVE-2025-61593HigOct 3, 2025
    risk 0.46cvss 7.1epss 0.00

    Cursor is a code editor built for programming with AI. In versions 1.7 and below, a vulnerability in the way Cursor CLI Agent protects its sensitive files (i.e. */.cursor/cli.json) allows attackers to modify the content of the files through prompt injection, thus achieving…

  • CVE-2025-54131MedAug 1, 2025
    risk 0.42cvss 6.4epss 0.00

    Cursor is a code editor built for programming with AI. In versions below 1.3, an attacker can bypass the allow list in auto-run mode with a backtick (`) or $(cmd). If a user has swapped Cursor from its default settings (requiring approval for every terminal call) to an…

  • CVE-2025-61589MedOct 3, 2025
    risk 0.38cvss 5.9epss 0.00

    Cursor is a code editor built for programming with AI. In versions 1.6 and below, Mermaid (a to render diagrams) allows embedding images which then get rendered by Cursor in the chat box. An attacker can use this to exfiltrate sensitive information to a third-party attacker…

  • CVE-2025-49150MedJun 11, 2025
    risk 0.38cvss 5.9epss 0.00

    Cursor is a code editor built for programming with AI. Prior to 0.51.0, by default, the setting json.schemaDownload.enable was set to True. This means that by writing a JSON file, an attacker can trigger an arbitrary HTTP GET request that does not require user confirmation.…

  • CVE-2025-9190MedAug 26, 2025
    risk 0.31cvss epss 0.00

    The configuration of Cursor on macOS, specifically the "RunAsNode" fuse enabled, allows a local attacker with unprivileged access to execute arbitrary code that inherits Cursor TCC (Transparency, Consent, and Control) permissions. Acquired resource access is limited to…

  • CVE-2025-54132MedAug 1, 2025
    risk 0.29cvss 4.4epss 0.00

    Cursor is a code editor built for programming with AI. In versions below 1.3, Mermaid (which is used to render diagrams) allows embedding images which then get rendered by Cursor in the chat box. An attacker can use this to exfiltrate sensitive information to a third-party…

  • CVE-2024-45599LowSep 25, 2024
    risk 0.25cvss 3.8epss 0.00

    Cursor is an artificial intelligence code editor. Prior to version 0.41.0, if a user on macOS has granted Cursor access to the camera or microphone, any program that is run on the machine is able to access the camera or the microphone without explicitly being granted access,…

  • CVE-2026-61613HigJul 15, 2026
    risk 0.00cvss epss 0.00

    Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled web content to connect from inside the agent container to an unauthenticated local agent endpoint, enabling…

  • CVE-2026-50549CriJun 25, 2026
    risk 0.00cvss 9.8epss 0.01

    Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, the agent canonicalizes the target path to confirm it stays inside the workspace, but when canonicalization fails it falls back to…

  • CVE-2026-50548CriJun 25, 2026
    risk 0.00cvss 9.8epss 0.01

    Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox grants write access to the command's working directory. A flaw was identified in how the agent could modify the working_directory…

Page 2 of 2