Anysphere develops the Cursor code-editor product, which has emerged as a more prominent target in the vulnerability landscape despite a narrow portfolio footprint. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and concentrate around command injection, code injection, sensitive information exposure, path traversal, and case-sensitivity handling—weakness classes typical of editor tools that process untrusted input and interact with the operating system and filesystem. Defenders integrating this tool into development environments should prioritize patching and monitor for variants of these input-handling and access-control weaknesses; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Anysphere over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-50548CRITICAL Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox grants write access to the command | Jun 25, 2026 | 9.8 | 47 | NO | NO |
CVE-2026-50549CRITICAL Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, the agent canonicalizes the target | Jun 25, 2026 | 9.8 | 47 | NO | NO |
CVE-2025-54136HIGH Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and persistent code execution by modifying an already trusted MCP c | Aug 2, 2025 | 8.8 | 39 | NO | NO |
CVE-2026-26268CRITICAL Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection) | Feb 13, 2026 | 9.9 | 38 | NO | NO |
CVE-2025-54135CRITICAL Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions below 1.3.9, If the file is a dotfile, editing it | Aug 5, 2025 | 9.8 | 37 | NO | NO |
CVE-2026-22708CRITICAL Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, certain shell built-ins can still | Jan 14, 2026 | 9.8 | 36 | NO | NO |
CVE-2025-54130CRITICAL Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions less than 1.3.9. If the file is a dotfile, editing | Aug 5, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-59944CRITICAL Cursor is a code editor built for programming with AI. Versions 1.6.23 and below contain case-sensitive checks in the way Cursor IDE protects its sensitive files (e.g., */.cursor/m | Oct 3, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-61591HIGH Cursor is a code editor built for programming with AI. In versions 1.7 and below, when MCP uses OAuth authentication with an untrusted MCP server, an attacker can impersonate a mal | Oct 3, 2025 | 8.8 | 30 | NO | NO |
CVE-2025-64108HIGH Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a prompt injection attacker to circumvent sensitive file protect | Nov 4, 2025 | 8.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Anysphere.
Media articles that mention a CVE ID that affects a product developed by Anysphere — matched by CVE ID, not by vendor name.