Skip to content
CursorGHSA-whx2-4gvm-m3r3

Cloud Agent Browser Sandbox Escape

High7.7CVE-2026-61613 · Published Jul 6, 2026 · updated Jul 10, 2026

### Impact A vulnerability in browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled web content to connect from inside the agent container to an unauthenticated local agent endpoint. Successful exploitation allowed code execution within the affected Cloud Agent sandbox/session. An attacker could access files, repository contents, environment variables, and credentials available to that session. Cloud Agent sessions include GitHub App access tokens for repository operations. Exposure of these tokens allows read/write access to the associated repository, including code, pull requests, checks, and workflows, subject to the agent’s granted permissions. If customers configured additional secrets, such as cloud credentials, CI/CD tokens, or API keys, downstream impact to external systems could be higher depending on those credentials’ permissions. Exploitation requires: - A browser-capable Cloud Agent configuration. - An agent/browser flow that loaded attacker-controlled content. ### Patches The issue has been patched in Cursor Cloud Agents. We upgraded the Cloud Agent environment so affected sessions require authentication for the relevant agent control channel....

GitHub advisory

Affected versions

PackageAffectedFixed in
cursor
Product
< Fixedon03/31/2026Fixedon03/31/2026
Details and references

### Impact A vulnerability in browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled web content to connect from inside the agent container to an unauthenticated local agent endpoint. Successful exploitation allowed code execution within the affected Cloud Agent sandbox/session. An attacker could access files, repository contents, environment variables, and credentials available to that session. Cloud Agent sessions include GitHub App access tokens for repository operations. Exposure of these tokens allows read/write access to the associated repository, including code, pull requests, checks, and workflows, subject to the agent’s granted permissions. If customers configured additional secrets, such as cloud credentials, CI/CD tokens, or API keys, downstream impact to external systems could be higher depending on those credentials’ permissions. Exploitation requires: - A browser-capable Cloud Agent configuration. - An agent/browser flow that loaded attacker-controlled content. ### Patches The issue has been patched in Cursor Cloud Agents. We upgraded the Cloud Agent environment so affected sessions require authentication for the relevant agent control channel. No user action is required for Cursor-hosted Cloud Agents. ### CVSS CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L ### Reporter Credit to Arbër Salihi (@arber-salihi) Lead Product Security Engineer, Thomson Reuters

CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-306

More Cursor advisories

All Cursor

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.