Cursor
Vendor:
First CVE: Aug 1, 2025 · Active for under a year
21
Total CVEs
More Total CVEs than 94% of tracked products
10.5
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
8.8
Avg CVSS
Higher Avg CVSS than 82% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cursor over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 1, 2025
11 months ago
Most Recent CVE
Jun 25, 2026
29 days ago
CVE Severity & Scoring
Cursor21 CVEs
57%
38%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network21 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (90.5%)
High2 (9.5%)
Unknown0 (0.0%)
User Interaction
None14 (66.7%)
Unknown0 (0.0%)
Required7 (33.3%)
Privileges Required
Low5 (23.8%)
High0 (0.0%)
None16 (76.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-50548CRITICAL Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox grants write access to the command | Jun 25, 2026 | 9.8 | 47 | NO | NO |
CVE-2026-50549CRITICAL Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, the agent canonicalizes the target | Jun 25, 2026 | 9.8 | 47 | NO | NO |
CVE-2025-54136HIGH Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and persistent code execution by modifying an already trusted MCP c | Aug 2, 2025 | 8.8 | 39 | NO | NO |
CVE-2026-26268CRITICAL Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection) | Feb 13, 2026 | 9.9 | 38 | NO | NO |
CVE-2025-54135CRITICAL Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions below 1.3.9, If the file is a dotfile, editing it | Aug 5, 2025 | 9.8 | 37 | NO | NO |
CVE-2026-22708CRITICAL Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, certain shell built-ins can still | Jan 14, 2026 | 9.8 | 36 | NO | NO |
CVE-2025-54130CRITICAL Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions less than 1.3.9. If the file is a dotfile, editing | Aug 5, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-59944CRITICAL Cursor is a code editor built for programming with AI. Versions 1.6.23 and below contain case-sensitive checks in the way Cursor IDE protects its sensitive files (e.g., */.cursor/m | Oct 3, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-61591HIGH Cursor is a code editor built for programming with AI. In versions 1.7 and below, when MCP uses OAuth authentication with an untrusted MCP server, an attacker can impersonate a mal | Oct 3, 2025 | 8.8 | 30 | NO | NO |
CVE-2025-64108HIGH Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a prompt injection attacker to circumvent sensitive file protect | Nov 4, 2025 | 8.8 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (21 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (21 CVEs).
Media Mentions
Signals from CVEs in this product scope (21 CVEs).
Top CNAs Publishing CVEs For Cursor
Top CWEs
Versions
No cataloged versions.