CVE-2026-61613 Details
Description
Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled web content to connect from inside the agent container to an unauthenticated local agent endpoint, enabling code execution within the affected Cloud Agent sandbox or session and access to files, repository contents, environment variables, credentials, and GitHub App access tokens available to that session. This issue was fixed on 03/31/2026 by requiring authentication for the relevant agent endpoint.
A vulnerability existed in browser-enabled Cursor Cloud Agent sessions prior to the fix on March 31, 2026. This issue allowed attacker-controlled web content to connect from inside the agent container to an unauthenticated local agent endpoint. Exploitation of this vulnerability enabled code execution within the affected Cloud Agent sandbox or session. Additionally, it allowed access to files, repository contents, environment variables, credentials, and GitHub App access tokens available to that session. The vulnerability could be exploited by loading attacker-controlled content in a browser-capable Cloud Agent configuration.
The vulnerability has been patched in Cursor Cloud Agents. Affected sessions now require authentication for the relevant agent control channel. No user action is required for Cursor-hosted Cloud Agents.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 15, 2026CISA-ADP
Assessed Jul 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cursor/cursor/security/advisories/GHSA-whx2-4gvm-m3r3 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Cursor | All versions |
CPE
Remediation
| |
| Cursor Cloud Agent | < 2026-03-31 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | New CVE Received | [email protected] |
Volerion