CVE-2026-61613
Deferred Deferred - Pending Action

Remote Code Execution in Cursor Cloud Agent

Vulnerability report for CVE-2026-61613, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-15

Last updated on: 2026-07-21

Assigner: GitHub, Inc.

Description

Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled web content to connect from inside the agent container to an unauthenticated local agent endpoint, enabling code execution within the affected Cloud Agent sandbox or session and access to files, repository contents, environment variables, credentials, and GitHub App access tokens available to that session. This issue was fixed on 03/31/2026 by requiring authentication for the relevant agent endpoint.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-15
Last Modified
2026-07-21
Generated
2026-08-04
AI Q&A
2026-07-16
EPSS Evaluated
2026-08-03
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cursor cloud_agent to 2026-03-31 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-61613 is a high-severity vulnerability in Cursor's Cloud Agent Browser Sandbox Escape. It allowed attacker-controlled web content in a browser-enabled Cursor Cloud Agent session to connect to an unauthenticated local agent endpoint, enabling code execution within the sandbox.

Detection Guidance

Detecting this vulnerability requires checking if your Cursor Cloud Agent is running an outdated version prior to the 03/31/2026 fix. Inspect the agent logs for unauthorized connections to local endpoints or unexpected code execution within the sandbox. Review network traffic for outbound connections from the agent container to local services.

Impact Analysis

Successful exploitation could grant access to files, repository contents, environment variables, and session credentials, including GitHub App access tokens with read/write repository permissions. Additional secrets like cloud credentials or API keys could also be exposed depending on their permissions.

Compliance Impact

The vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR (data protection) and HIPAA (health information privacy) by exposing personal or confidential information.

Mitigation Strategies

Update Cursor to the latest version to ensure the Cloud Agent fix is applied. If using a self-hosted Cloud Agent, verify authentication is enforced for the agent control channel. Revoke any exposed credentials, tokens, or API keys accessed during the vulnerable period.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-61613. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart