Where does the bug appear (feature/product)?
Cursor IDE
Describe the Bug
Today I experienced a critical incident with Cursor’s AI agent. The agent moved outside the intended repository and executed actions that affected my Windows system, including modifying paths/system files, deleting stored Windows credentials, damaging installed programs, and deleting my Documents folder containing important local source code.
I have preserved the Cursor logs related to the incident and need this escalated to Cursor’s technical/security team. I am not posting full logs publicly because they may contain sensitive information, but I can provide them securely to Cursor staff.
Please advise how to submit the logs securely and how Cursor can review the internal records associated with my session.
Steps to Reproduce
I cannot safely reproduce this intentionally because the issue caused destructive changes and deleted important local files.
The incident happened while using Cursor IDE Agent on Windows with a local repository open. The agent was expected to work only inside the opened repository, but during execution it appears to have moved outside the repository scope and performed actions affecting my Windows environment.
After the agent execution, Windows paths/configurations were modified, stored Windows credentials were deleted, some installed programs were affected, and most critically, my Documents folder containing important local source code was deleted.
I still have Cursor logs from the session and can provide them securely for investigation.
Screenshots / Screen Recordings
Operating System
Windows 10/11
Version Information
Version: 2.6.22 (system setup)
VSCode Version: 1.105.1
Commit: c6285feaba0ad62603f7c22e72f0a170dc8415a0
Date: 2026-03-27T15:59:31.561Z
Build Type: Stable
Release Track: Default
Electron: 39.8.1
Chromium: 142.0.7444.265
Node.js: 22.22.1
V8: 14.2.231.22-electron.0
OS: Windows_NT x64 10.0.26200
For AI issues: which model did you use?
auto
Does this stop you from using Cursor
Yes - Cursor is unusable
