Known Vulnerabilities for Cursor by Anysphere
Listed below are 2 of the newest known vulnerabilities associated with "Cursor" by "Anysphere".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-56307 json | Cap-go before 12.128.12 contains a broken cursor pagination vulnerability in the /private/devices endpoint on the Cloudflare/... | Not Provided | 2026-06-20 | 2026-06-22 |
| CVE-2026-56221 json | Cap-go before 12.128.2 contains multiple SQL injection vulnerabilities in cloudflare.ts where user-controlled values from API... | Not Provided | 2026-06-22 | 2026-06-23 |
| CVE-2026-53655 json | node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (an... | Not Provided | 2026-06-22 | 2026-06-23 |
| CVE-2026-53190 json | In the Linux kernel, the following vulnerability has been resolved: drm/virtio: fix dma_fence refcount leak on error in virt... | Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2026-52965 json | In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Fix ttm_bo_swapout() infinite LRU walk on swapo... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-52722 json | A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimens... | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-50549 json | Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by defa... | Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2026-50548 json | Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by defa... | Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2026-48124 json | Cursor is a code editor built for programming with AI. In versions prior to 3.0.0, the Cursor Desktop could execute workspace... | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-46227 json | In the Linux kernel, the following vulnerability has been resolved: sctp: revalidate list cursor after sctp_sendmsg_to_asoc(... | Not Provided | 2026-05-28 | 2026-06-01 |