Anysphere
16 CVEs tracked since 2025. Since Aug 2025, none of them reached CISA KEV.
Anysphere CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-08 | 6 | 0 |
| 2025-09 | null or fewer | |
| 2025-10 | 6 | 0 |
| 2025-11 | 4 | 0 |
Products
The products that kept showing up in Anysphere's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Anysphere.
- CVE-2026-63093Cursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace8.8
- CVE-2026-50548Cursor Desktop sandbox escape via agent-controlled working directory9.8
- CVE-2026-50549Cursor Desktop sandbox escape via symlink and failed path canonicalization9.8
- CVE-2026-31854Cursor Affected by Arbitrary Code Execution via Prompt Injection and Whitelist Bypass8.8
- CVE-2026-26268Cursor sandbox escape via Git hooks8.0
- CVE-2026-22708Cursor has a Terminal Tool Allowlist Bypass via Environment Variables9.8
- CVE-2025-64110Cursor: Authentication Bypass Possible via New Cursorignore Write7.5
- CVE-2025-64108Cursor's Sensitive File Modification can Lead to NTFS Path Quirks8.8
- CVE-2025-64107Cursor is Vulnerable to Path Manipulation Using Backslashes on Windows8.8
- CVE-2025-64106Cursor: Speedbump Modal Bypass in MCP Server Deep-Link8.8
- CVE-2025-59944Cursor IDE: Sensitive File Overwrite Bypass is Possible8.0
- CVE-2025-61593Cursor CLI Agent: Sensitive File Overwrite Bypass7.1
- CVE-2025-61592Cursor CLI: Arbitrary Code Execution Possible through Permissive CLI Config8.8
- CVE-2025-61591Cursor CLI's Cursor Agent MCP OAuth2 Communication is Vulnerable to Remote Code Execution8.8
- CVE-2025-61590Cursor is vulnerable to RCE via .code-workspace files using Prompt Injection7.5
The record
- Peak rank
- #131 in Aug 2025
- Busiest month shown
- Aug 2025, 6 CVEs
- Months with a KEV entry
- 0 since Aug 2025
- Monthly snapshots
- 3 since 2025