|
Security Issue: Debug Mode Credential Exposure (Sonnet 4.5)
|
|
1
|
12
|
March 5, 2026
|
|
Enable TUN/TAP device support in Cloud Agent VMs for VPN connectivity
|
|
0
|
17
|
March 4, 2026
|
|
Where are Cloud Instance hosted?
|
|
1
|
18
|
March 4, 2026
|
|
Cursor-sandbox-remote AppArmor profile missing abi declaration and network rule — breaks sandbox on Ubuntu 24.04+
|
|
2
|
80
|
March 4, 2026
|
|
Personal Data Breach in Cursor Dashboard Analytics Page
|
|
4
|
29
|
March 4, 2026
|
|
Legit Email Address?
|
|
3
|
31
|
March 4, 2026
|
|
Codex Spark - Be careful when using
|
|
0
|
51
|
March 3, 2026
|
|
Cursor requests Apple Music access when exploring a different repo — unrelated to task or codebase
|
|
4
|
38
|
March 2, 2026
|
|
Runaway agent does things on its own
|
|
2
|
33
|
March 2, 2026
|
|
Blocked messages (BeforeSubmitPrompt hook returns continue: false) are still included in later LLM context/history
|
|
2
|
100
|
March 2, 2026
|
|
Dot env files are being read by the agent
|
|
2
|
40
|
February 28, 2026
|
|
Cursor reads files on my local filesystem onside projects workspace
|
|
2
|
33
|
February 26, 2026
|
|
.cursorignore blocks file read and bash commands, but not the Grep tool
|
|
2
|
28
|
February 25, 2026
|
|
Cursor Automatic Updater
|
|
2
|
51
|
February 24, 2026
|
|
Making Cursor Think Like a Hacker: A Security Guide for Vibe Coders
|
|
0
|
131
|
February 24, 2026
|
|
beforeShellExecution hook: malformed JSON response silently allows command instead of blocking
|
|
1
|
21
|
February 23, 2026
|
|
Cursor 2.5: Sandbox Network Access Controls
|
|
7
|
438
|
February 22, 2026
|
|
Read files outside the project folder
|
|
1
|
35
|
February 19, 2026
|
|
[Feature Request] Self-Service DPA for Pro/Business Plans
|
|
0
|
21
|
February 19, 2026
|
|
Cursor reads .env files by default
|
|
5
|
81
|
February 18, 2026
|
|
Autocomplete in .env file
|
|
2
|
106
|
February 16, 2026
|
|
Cursor IDE Agent Reads .env file!
|
|
2
|
95
|
February 15, 2026
|
|
Agent cannot run git push or other authenticated commands — no access to user credentials
|
|
4
|
102
|
March 3, 2026
|
|
RCE Vulnerability
|
|
2
|
39
|
February 9, 2026
|
|
Microsoft Defender detects Cursor update as Trojan:Win32/Wacatac.B!ml and Trojan:Script/Wacatac
|
|
2
|
150
|
March 3, 2026
|
|
Cursor Agents with access to our VPN or environment variables
|
|
2
|
107
|
March 3, 2026
|
|
Cursor agents should be restricted from access of files outside the project without permission
|
|
1
|
170
|
February 9, 2026
|
|
Cursor still calls the wrong MCP tools - SUPER DANGEROUS
|
|
3
|
64
|
February 28, 2026
|
|
Controlling LLM Context Exposure in Cursor: cursorignore, shell commands, and fine-grained allowlists
|
|
0
|
53
|
February 5, 2026
|
|
Serious macOS issue: ASafari folder + Dock Safari replaced/force‑closed after enabling Cursor terminal access
|
|
3
|
30
|
February 24, 2026
|