I can't log in to the Cursor account

Where does the bug appear (feature/product)?

Somewhere else…

Describe the Bug

The problem is this: when I enter my account details, email, and password, I receive a code and am redirected to the settings page, but when I load the settings page, I am redirected to the login page.

I tried to clear the cache cookies, but it didn’t help.

Steps to Reproduce

login menu - enter your account details - it takes you to the cursor settings - after a second, it returns to the login screen

Operating System

Windows 10/11

Current Cursor Version (Menu → About Cursor → Copy)

Version: 2.0.69 (user setup)
VSCode Version: 1.99.3
Commit: 63fcac100bd5d5749f2a98aa47d65f6eca61db30
Date: 2025-11-07T18:21:29.650Z
Electron: 37.7.0
Chromium: 138.0.7204.251
Node.js: 22.20.0
V8: 13.8.258.32-electron.0
OS: Windows_NT x64 10.0.22631

Does this stop you from using Cursor

Yes - Cursor is unusable

hi @Max_Smith and thank you for the bug report.

Could you provide more info so we can check what is causing it:

  • Which browser did you use?
  • Was there any error in Console in the browser?
  • Does same issue occur with another browser?
  • Was that the email / password login or a social login Google/Apple?

Yes I tried several browsers. My regular Google just like me tried this option in Yandex browser as you seemed.

What was written in the console at login

Yandex Browser:
[For report only] Refused to execute inline script because it violates the following Content Security Policy directive: “script-src ‘self’ 'nonce-ADTCcE7b/5IRng7aZ1kyPg==‘unsafe-inline’ ”. Note that ‘unsafe-inline’ is ignored if either a hash value or a one-time value is present in the list of sources.
3905.799b9ecf80dd7578.js:610 The “unsafe-inline” content security policy directive is ignored when using a report-only policy.
3905.799b9ecf80dd7578.js:610 phone number
3905.799b9ecf80dd7578.js:610 The “unsafe update requests” content security policy directive is ignored when using the report-only policy.
3905.799b9ecf80dd7578.js:610
9[Report-only] Denied

Google chrome:
Executing inline script violates the following Content Security Policy directive ‘script-src ‘self’ ‘nonce-cJE5/uXi+7IJ2+60ojdeIg==’ ‘unsafe-inline’ ’. Note that ‘unsafe-inline’ is ignored if either a hash or nonce value is present in the source list. The policy is report-only, so the violation has been logged but no further action has been taken.
3905.799b9ecf80dd7578.js:610 The Content Security Policy directive ‘upgrade-insecure-requests’ is ignored when delivered in a report-only policy.
(anonymous) @ 3905.799b9ecf80dd7578.js:610
3905.799b9ecf80dd7578.js:610 The Content Security Policy directive ‘upgrade-insecure-requests’ is ignored when delivered in a report-only policy.
(anonymous) @ 3905.799b9ecf80dd7578.js:610
9Evaluating a string as JavaScript violates the following Content Security Policy directive because ‘unsafe-eval’ is not an allowed source of script: “script-src ‘self’ ‘nonce-cJE5/uXi+7IJ2+60ojdeIg==’ ‘unsafe-inline’ ”.
The policy is report-only, so the violation has been logged but no further action has been taken.
3905.799b9ecf80dd7578.js:160 Canvas2D: Multiple readback operations using getImageData are faster with the willReadFrequently attribute set to true. See: HTML Standard
u @ 3905.799b9ecf80dd7578.js:160
CursorGothic-Regular.woff2:1 Failed to load resource: net::ERR_CONNECTION_RESET
CursorGothic-Bold.woff2:1 Failed to load resource: net::ERR_CONNECTION_RESET

The type of entry is mail

This topic was automatically closed 22 days after the last reply. New replies are no longer allowed.