Vulnerability Description
Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled web content to connect from inside the agent container to an unauthenticated local agent endpoint, enabling code execution within the affected Cloud Agent sandbox or session and access to files, repository contents, environment variables, credentials, and GitHub App access tokens available to that session. This issue was fixed on 03/31/2026 by requiring authentication for the relevant agent endpoint.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-61613?
CVE-2026-61613 is a documented vulnerability. Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled web content to connect from i...
How severe is CVE-2026-61613?
CVSS scoring is not yet available for CVE-2026-61613. Check NVD for updates.
Is there a patch for CVE-2026-61613?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.