PT-2026-60188 · Cursor · Cursor
CVE-2026-61613
·
Published
2026-07-15
·
Updated
2026-07-21
CVSS v4.0
7.7
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Cursor versions prior to 03/31/2026
Description
Browser-enabled Cloud Agent sessions allow attacker-controlled web content to connect from within the agent container to an unauthenticated local agent endpoint. This allows for code execution inside the affected Cloud Agent sandbox or session, providing access to files, repository contents, environment variables, credentials, and GitHub App access tokens associated with that session.
Recommendations
Update to the version released on 03/31/2026 or later.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cursor