Where does the bug appear (feature/product)?
Cursor IDE
Describe the Bug
On August 13, 2026, while using Cursor Agent on Windows, a destructive operation affected data across my separate 1TB D: drive.
I want to state the most important fact clearly:
I never instructed Cursor to delete, erase, wipe, format, initialize, or destroy my D: drive.
The work I had instructed Cursor to perform concerned work on my C: drive. My D: drive was being used to preserve completed software projects, business materials, backups, and other important data.
I therefore need to understand how an Agent operation associated with work elsewhere could result in a destructive operation affecting data across a separate D: drive.
The incident caused severe disruption to active software-development and business projects.
I have preserved Cursor-related records and created a near-complete forensic image of the affected physical drive. Recovery and reconstruction work is ongoing and being documented.
I am not alleging intent. I am requesting a technical explanation of how this destructive operation occurred and why the available safeguards did not prevent it.
Steps to Reproduce
I will not intentionally attempt to reproduce this incident on a live drive because doing so could cause further destructive data loss.
At the time of the incident, I had instructed Cursor Agent to perform work related to my C: drive. I gave no instruction whatsoever to delete, erase, wipe, format, initialize, or otherwise modify my D: drive.
Nevertheless, during the Agent session, a destructive operation was executed, and data across my separate 1TB D: drive was deleted on a massive scale.
I have preserved relevant Cursor records, session information, recovery evidence, and a near-complete forensic image of the affected physical drive.
Because intentionally reproducing this incident could cause additional catastrophic data loss, I ask Cursor/Anysphere to use the preserved server-side and session records to reconstruct the exact command, execution path, resolved target path, and technical cause of the incident.
Expected Behavior
Cursor Agent should remain within the scope of the user’s requested task.
A development task associated with C: should never result in destructive modification or recursive deletion across an unrelated D: drive unless the user explicitly requests and confirms that exact operation.
If an Agent-generated command:
- targets a drive root such as
C:\orD:\, - resolves outside the intended workspace,
- performs recursive deletion,
- changes target because of quoting, escaping, shell translation, or path-resolution behavior,
- or could affect data far beyond the intended folder,
Cursor should block the command or require clear, explicit user confirmation showing the fully resolved destructive target before execution.
A malformed or incorrectly resolved deletion command should fail safely rather than expand into drive-wide data loss.
Operating System
Windows 10/11
Version Information
IDE:
Incident date: August 13, 2026
Operating System: Windows 11
Exact Cursor IDE version at the time of the incident is currently being verified from preserved Cursor session/log records.
The currently installed Cursor version may differ from the version used at the time of the incident.
For AI issues: which model did you use?
Exact model used at the time of the August 13, 2026 incident is currently being verified from preserved Cursor session/log records.
I do not want to provide an unverified model name.
For AI issues: add Request ID with privacy disabled
The exact Request ID for the destructive operation is currently being recovered and verified from preserved Cursor records.
I request that Cursor/Anysphere also identify the Request ID and associated tool-call/session records from its retained server-side records for the August 13, 2026 incident.
Additional Information
I am writing this because I still cannot understand how work I requested on C: resulted in massive deletion on a separate D: drive where I had deliberately stored completed projects and backups for safety.
This incident is not a minor software malfunction.
I am a paying Cursor Pro user, and the affected 1TB D: drive contained completed software projects developed with Cursor Agent, core business materials, backups, project assets, and other work accumulated over a long period of time.
At the time of the incident, I had instructed Cursor Agent to perform work associated with my C: drive. I did not instruct Cursor to delete, erase, wipe, format, initialize, or destroy my separate D: drive.
Nevertheless, a destructive Agent operation affected data across that separate drive on a massive scale.
The incident has caused substantial disruption to my software-development work, business plans, project schedules, and recovery efforts.
I formally reported this incident to Anysphere and requested preservation of relevant records and a substantive technical explanation of the cause.
What concerns me greatly is that, before I received the detailed technical findings I requested regarding the exact command, execution path, resolved deletion target, and safeguards involved, the response I received relied in part on limitation-of-liability provisions.
I subsequently reviewed multiple serious Windows data-deletion incidents publicly reported in the Cursor Community during 2026.
In some of those discussions, Cursor personnel publicly discussed destructive shell commands, Windows quoting/path-resolution behavior, deletion extending beyond the intended target, limitations of existing protections, and related failure modes that had already been reported or were being tracked.
I am not claiming that every prior incident is technically identical to mine.
However, these prior reports raise a serious and unavoidable question:
If Anysphere was already aware that a Windows Agent shell command could, under certain conditions, expand beyond its intended deletion target and potentially affect a drive root or data outside the workspace, why was such a catastrophic operation still technically possible on August 13, 2026?
Why was a recursive destructive operation resolving to C:, D:, another volume root, the user home directory, or a location outside the intended workspace not hard-blocked or subjected to mandatory, explicit user confirmation showing the fully resolved target?
I also believe there is an important user-awareness issue.
If an Agent feature is capable of causing catastrophic local data loss despite existing safeguards, users should receive a prominent and explicit warning about that risk before allowing the Agent to execute destructive shell commands.
This becomes even more important where the company’s Terms may seek to substantially limit its financial responsibility after such a loss occurs.
I am not alleging here that Anysphere intentionally concealed information, and I am not asking this community to determine legal liability.
I am asking why a catastrophic risk that appears to have been discussed in multiple prior public incidents was not prevented at the product level or prominently disclosed to users before my incident occurred.
I have preserved Cursor-related records, session information, recovery evidence, and a near-complete forensic image of the affected physical drive.
Recovery and reconstruction are still ongoing.
I am also documenting the time and cost required to recover and rebuild the software and business assets affected by this incident.
I am still using Cursor only in a limited and closely supervised manner because I need it to assist with recovery and reconstruction.
That continued use should not be interpreted as meaning that the issue has been resolved or that I consider normal autonomous use safe.
I ask Cursor/Anysphere to provide a substantive technical response addressing:
- The exact destructive command generated and executed.
- The intended deletion target.
- The actual target resolved by Windows.
- The shell, working directory, quoting/escaping, and path-resolution process involved.
- The Run Mode, approval state, and safeguards active during the incident.
- Whether any safeguard detected or attempted to stop the destructive operation.
- Whether my incident is related to, or technically distinct from, previously reported Windows destructive-deletion failure modes.
- What product-level safeguard had been implemented before August 13, 2026 to prevent an Agent-generated recursive delete from expanding to a drive root.
- Why that safeguard did not prevent this incident.
I will not publish private correspondence, confidential information, credentials, or settlement communications here.
My purpose in documenting this publicly is to establish an accurate technical record of my own incident, obtain a substantive explanation from Cursor/Anysphere, and raise a legitimate product-safety concern so that this type of catastrophic data loss is properly addressed.
I trusted Cursor enough to use it extensively as part of my actual software-development and business work.
I therefore expect a response consistent with the seriousness of the incident and the level of responsibility users should reasonably expect from the Cursor brand.
My dispute with Anysphere remains unresolved.
Does this stop you from using Cursor
Sometimes - I can sometimes use Cursor