Impact
The vulnerability allows attacker-controlled web content delivered to a browser-enabled Cursor Cloud Agent session to reach an unauthenticated local agent endpoint inside the agent container. Because the endpoint lacks authentication, the attacker can execute arbitrary code within the sandbox and read or modify files, repository contents, environment variables, credentials, or GitHub App access tokens that belong to that session. The flaw is a missing authentication weakness that directly compromises the confidentiality, integrity, and availability of the affected code editing environment.
Affected Systems
Vendor cursor:cursor and its Cloud Agent component are affected. Versions released before the fix on 03/31/2026 include this flaw. The specific version numbers are not listed in the advisory, so any installation that predates the 03/31/2026 update should be considered vulnerable.
Risk and Exploitability
The CVSS score high‑severity flaw while the EPSS score of less than 1% shows a low probability of exploitation at the time of this analysis. Although it is not listed in the CISA KEV catalog, attackers can exploit it remotely by injecting malicious web content into the Cursor browser session that composes the Cloud Agent. Once the unauthenticated agent endpoint is accessed, arbitrary code can run with the permissions of the session holder, providing broad data access and potential lateral movement.
OpenCVE Enrichment