Cursor
19 CVEs tracked since 2025. Since Aug 2025, none of them reached CISA KEV.
Cursor CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-08 | 7 | 0 |
| 2025-09 | null or fewer | |
| 2025-10 | 6 | 0 |
| 2025-11 | 6 | 0 |
Products
The products that kept showing up in Cursor's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Cursor.
- CVE-2026-73218Cursor: Sandbox escape via launching privileged containers—
- CVE-2026-73217Cursor: Sandbox escape via tampered Python virtual environments—
- CVE-2026-61613Cursor: Cloud Agent Browser Sandbox Escape—
- CVE-2026-50548Cursor Desktop sandbox escape via agent-controlled working directory9.8
- CVE-2026-50549Cursor Desktop sandbox escape via symlink and failed path canonicalization9.8
- CVE-2026-48124Cursor Desktop sandbox escape via Claude hook configuration—
- CVE-2026-31854Cursor Affected by Arbitrary Code Execution via Prompt Injection and Whitelist Bypass8.8
- CVE-2026-26268Cursor sandbox escape via Git hooks8.0
- CVE-2026-22708Cursor has a Terminal Tool Allowlist Bypass via Environment Variables9.8
- CVE-2025-62354Improper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized attacker to execute commands that are outside of those specified in the allo...9.8
- CVE-2025-64110Cursor: Authentication Bypass Possible via New Cursorignore Write7.5
- CVE-2025-64109Cursor CLI Beta: Command Injection via Untrusted MCP Configuration8.8
- CVE-2025-64108Cursor's Sensitive File Modification can Lead to NTFS Path Quirks8.8
- CVE-2025-64107Cursor is Vulnerable to Path Manipulation Using Backslashes on Windows8.8
- CVE-2025-64106Cursor: Speedbump Modal Bypass in MCP Server Deep-Link8.8
The record
- Peak rank
- #116 in Aug 2025
- Busiest month shown
- Aug 2025, 7 CVEs
- Months with a KEV entry
- 0 since Aug 2025
- Monthly snapshots
- 3 since 2025