Junglewise Threat Intelligence

CVE-2026-61613: Cursor Cloud Agent authentication bypass in local agent endpoint

CVE-2026-61613 · Severity: info · CVSS 7.7 · Published 2026-07-15

Executive brief

Cursor is an AI-powered code editor that provides cloud-based environments for software development. A security flaw in the Cloud Agent allowed malicious websites to bypass security boundaries and execute code within a user's private development session. This could lead to the theft of source code, environment variables, and sensitive credentials like GitHub access tokens or cloud provider keys.

Technical details

A missing authentication vulnerability (CWE-306) existed in the browser-enabled Cursor Cloud Agent sessions. Attacker-controlled web content loaded within the agent's browser flow could connect to an unauthenticated local agent control endpoint inside the container. This allowed for a sandbox escape, enabling arbitrary code execution within the Cloud Agent session. An attacker could subsequently access the filesystem, environment variables, and GitHub App access tokens. The vulnerability was mitigated by requiring authentication for the relevant agent control channel.

Affected products

  • Cursor Cursor Cloud Agent Prior to 2026-03-31

Timeline

  • 2026-03-31: patched: Authentication required for agent endpoint
  • 2026-07-06: advisory: GitHub Security Advisory published
  • 2026-07-15: disclosed: CVE published to NVD

References