Skip to content
CursorGHSA-hf2x-r83r-qw5q

Arbitrary Code Execution via Prompt Injection and Whitelist Bypass

HighCVE-2026-31854 · Published Mar 9, 2026

### Summary Cursor is able to access arbitrary websites. If a visited website contains maliciously crafted instructions, the model may attempt to follow them in order to “assist” the user. When combined with a bypass of the command whitelist mechanism, such indirect prompt injections could result in commands being executed automatically, without the user’s explicit intent, thereby posing a significant security risk. ### Impact This vulnerability allows an attacker to achieve arbitrary command execution on a user’s system via the Cursor Agent, even when Auto‑Run Mode is set to “Use AllowList.” By serving malicious prompt‑injection content and bypassing the whitelist check, an attacker can execute commands without user consent, leading to potential system compromise. Any user who interacts with untrusted websites through the Cursor Agent is at risk.

GitHub advisory

Affected versions

PackageAffectedFixed in
Cursor
Product
< 2.02.0
Details and references

More Cursor advisories

All Cursor

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.