|
Cursor 2.5: Sandbox Network Access Controls
|
|
9
|
767
|
March 10, 2026
|
|
Why doesn't your script verify sha?
|
|
0
|
40
|
March 9, 2026
|
|
Security Issue: Debug Mode Credential Exposure (Sonnet 4.5)
|
|
6
|
50
|
March 30, 2026
|
|
!Reproducable! - Context pollution from a completely foreign project
|
|
3
|
71
|
April 2, 2026
|
|
Add Multi-Factor Authentication
|
|
0
|
50
|
March 6, 2026
|
|
Enable TUN/TAP device support in Cloud Agent VMs for VPN connectivity
|
|
0
|
71
|
March 4, 2026
|
|
Where are Cloud Instance hosted?
|
|
1
|
64
|
March 4, 2026
|
|
Cursor-sandbox-remote AppArmor profile missing abi declaration and network rule — breaks sandbox on Ubuntu 24.04+
|
|
3
|
606
|
March 26, 2026
|
|
Personal Data Breach in Cursor Dashboard Analytics Page
|
|
5
|
188
|
March 26, 2026
|
|
Legit Email Address?
|
|
3
|
87
|
March 4, 2026
|
|
Codex Spark - Be careful when using
|
|
0
|
98
|
March 3, 2026
|
|
Cursor requests Apple Music access when exploring a different repo — unrelated to task or codebase
|
|
5
|
170
|
March 24, 2026
|
|
Blocked messages (BeforeSubmitPrompt hook returns continue: false) are still included in later LLM context/history
|
|
3
|
137
|
March 24, 2026
|
|
Dot env files are being read by the agent
|
|
3
|
70
|
March 22, 2026
|
|
.cursorignore blocks file read and bash commands, but not the Grep tool
|
|
3
|
55
|
March 19, 2026
|
|
Cursor Automatic Updater
|
|
3
|
103
|
March 18, 2026
|
|
Making Cursor Think Like a Hacker: A Security Guide for Vibe Coders
|
|
0
|
241
|
February 24, 2026
|
|
beforeShellExecution hook: malformed JSON response silently allows command instead of blocking
|
|
2
|
27
|
March 17, 2026
|
|
Read files outside the project folder
|
|
2
|
122
|
March 13, 2026
|
|
[Feature Request] Self-Service DPA for Pro/Business Plans
|
|
0
|
56
|
February 19, 2026
|
|
Cursor reads .env files by default
|
|
6
|
333
|
March 12, 2026
|
|
Autocomplete in .env file
|
|
3
|
156
|
March 10, 2026
|
|
Cursor IDE Agent Reads .env file!
|
|
3
|
205
|
March 9, 2026
|
|
Agent cannot run git push or other authenticated commands — no access to user credentials
|
|
4
|
221
|
March 3, 2026
|
|
RCE Vulnerability
|
|
2
|
41
|
February 9, 2026
|
|
Microsoft Defender detects Cursor update as Trojan:Win32/Wacatac.B!ml and Trojan:Script/Wacatac
|
|
2
|
267
|
March 3, 2026
|
|
Cursor Agents with access to our VPN or environment variables
|
|
2
|
218
|
March 3, 2026
|
|
Cursor agents should be restricted from access of files outside the project without permission
|
|
1
|
332
|
February 9, 2026
|
|
Cursor still calls the wrong MCP tools - SUPER DANGEROUS
|
|
3
|
73
|
February 28, 2026
|
|
Controlling LLM Context Exposure in Cursor: cursorignore, shell commands, and fine-grained allowlists
|
|
0
|
64
|
February 5, 2026
|