PT-2026-60188 · Cursor · Cursor

CVE-2026-61613

·

Published

2026-07-15

·

Updated

2026-07-21

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Cursor versions prior to 03/31/2026
Description Browser-enabled Cloud Agent sessions allow attacker-controlled web content to connect from within the agent container to an unauthenticated local agent endpoint. This allows for code execution inside the affected Cloud Agent sandbox or session, providing access to files, repository contents, environment variables, credentials, and GitHub App access tokens associated with that session.
Recommendations Update to the version released on 03/31/2026 or later.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61613

Affected Products

Cursor