Security Concern: Files in .cursorignore accessible to agent if they are open in an editor tab?

There are currently bugs with the .cursorignore.

E.g., if no explicitly .cursorignore is provided, cursor is not ignoring ANY files. This is contrary to the documentation which states that the default ignore list if .gitignore + a default list ( Ignore files | Cursor Docs ). –> Reported here Upgrade to 2.4.21 removes global (default) cursorignore

Extremely concerning that the cursor team is not quickly reacting to these bugs, a security understanding unfit for a product used in industry.