|
Vulnerability Scanner: weekly/cron schedule requires a branch, but UI has no branch picker
|
|
2
|
20
|
August 10, 2026
|
|
Cursor breaks boundaries such as searching the disk or a different repository
|
|
1
|
19
|
August 9, 2026
|
|
Critical: Mac User Files Disappear After Cursor Keychain Issue
|
|
2
|
49
|
August 7, 2026
|
|
Cursor agents should be restricted from access of files outside the project without permission
|
|
6
|
894
|
August 6, 2026
|
|
Serious Boundary Issue bypass
|
|
8
|
91
|
August 5, 2026
|
|
Cursor/Claude Code deleted my entire Documents folder on macOS
|
|
2
|
85
|
August 5, 2026
|
|
Command Allowlist: an entry for a cmdlet that takes a script block auto-runs any command inside the braces
|
|
1
|
40
|
August 5, 2026
|
|
Command Allowlist: Always run widens the allowlist to a bare tool name without unblocking the command it was attached to
|
|
1
|
36
|
August 5, 2026
|
|
Security Agents: "trigger needs a branch selected" but no branch selector exists in the UI
|
|
2
|
52
|
August 5, 2026
|
|
Gitlab integration requires unreasonable access for teams
|
|
11
|
226
|
August 4, 2026
|
|
Command Allowlist: An entry naming a variable auto-runs any command on the right-hand side
|
|
1
|
31
|
August 4, 2026
|
|
Cloud Agent Secrets: updated and deleted secrets keep injecting stale values into new agents
|
|
1
|
31
|
August 3, 2026
|
|
[Windows] Agent Shell: rmdir /s with trailing \ before " escapes target and wipes volume root
|
|
3
|
39
|
July 30, 2026
|
|
On Windows, Cursor’s hook stdin JSON payload includes a UTF-8 BOM that breaks standard JSON.parse(), causing security guards to silently degrade to allowing commands across all agent channels
|
|
2
|
65
|
July 27, 2026
|
|
NEUS: Portable Trust Harness for Coding Agents
|
|
0
|
52
|
July 25, 2026
|
|
Platform-level audit trail for agent tool call proposals and user approval decisions
|
|
3
|
167
|
July 25, 2026
|
|
Flawed extension scanning - malicious extension from vsx got installed from vscode extension auto-transfer
|
|
1
|
36
|
July 23, 2026
|
|
Ultimate solo user: can’t enable Security Review Context on Approval Agent (team plan required)
|
|
4
|
52
|
July 22, 2026
|
|
Privacy and the forced "how did the agent do"
|
|
3
|
102
|
July 22, 2026
|
|
Cursor connects to multiple undocumented domains
|
|
5
|
206
|
July 22, 2026
|
|
Request for official public advisory or changelog entry for the git.exe (CWE-426) fix — and a clearer process for future disclosures
|
|
2
|
113
|
July 20, 2026
|
|
Internal System Prompt leaking to the user- Cursor CLI
|
|
1
|
41
|
July 20, 2026
|
|
Is this legit ? @link.com email after payment
|
|
2
|
51
|
July 20, 2026
|
|
Addressing the recent Mindgard report
|
|
0
|
491
|
July 15, 2026
|
|
Unable to enable security agents
|
|
3
|
56
|
July 15, 2026
|
|
Sandbox .cursorignore bypass: tracked ignored files readable via git object store
|
|
2
|
46
|
July 15, 2026
|
|
Request for Documentation: Bugbot repository isolation boundaries for GitLab
|
|
2
|
38
|
July 15, 2026
|
|
Local prompt and file-read gates for Cursor
|
|
0
|
32
|
July 14, 2026
|
|
Anthropic Cybersecurity Verification Program
|
|
1
|
137
|
July 13, 2026
|
|
.cursorignore sandbox exclusions may fail with very large ignored file trees
|
|
2
|
43
|
July 9, 2026
|