CyberRota Analysis
AI-GeneratedThe Cursor Cloud Agent in GitHub was vulnerable to an attack that allowed unauthorized web content to connect to an unauthenticated local agent endpoint, potentially enabling code execution and unauthorized access to sensitive files, environment variables, and GitHub App tokens. This vulnerability poses a significant risk to developers and organizations using Cursor for AI programming, as it could lead to data breaches or compromise of their repositories. Users of the Cursor Cloud Agent should prioritize applying the fix implemented on March 31, 2026, to mitigate these risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled web content to connect from inside the agent container to an unauthenticated local agent endpoint, enabling code execution within the affected Cloud Agent sandbox or session and access to files, repository contents, environment variables, credentials, and GitHub App access tokens available to that session. This issue was fixed on 03/31/2026 by requiring authentication for the relevant agent endpoint.