CVE-2026-61613 is a high-severity vulnerability in Cursor Cloud Agent that allows code execution. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled web content to connect from inside the agent container to an unauthenticated local agent endpoint, enabling code execution within the affected Cloud Agent sandbox or session and access to files, [truncated]
CVE-2026-48124 is a high-severity vulnerability (CVSS Score: 8.5) affecting Cursor, a code editor built for programming with AI. In versions prior to 3.0.0, the Cursor Desktop could execute workspace-defined Claude hook commands from `.claude/settings.local.json` without dedicated user approval. A malicious workspace or agent-created file could configure hooks that run local commands in the user's context [truncated]