Cloud Agent Browser Sandbox Escape
High7.7CVE-2026-61613 · Published Jul 6, 2026 · updated Jul 10, 2026
### Impact A vulnerability in browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled web content to connect from inside the agent container to an unauthenticated local agent endpoint. Successful exploitation allowed code execution within the affected Cloud Agent sandbox/session. An attacker could access files, repository contents, environment variables, and credentials available to that session. Cloud Agent sessions include GitHub App access tokens for repository operations. Exposure of these tokens allows read/write access to the associated repository, including code, pull requests, checks, and workflows, subject to the agent’s granted permissions. If customers configured additional secrets, such as cloud credentials, CI/CD tokens, or API keys, downstream impact to external systems could be higher depending on those credentials’ permissions. Exploitation requires: - A browser-capable Cloud Agent configuration. - An agent/browser flow that loaded attacker-controlled content. ### Patches The issue has been patched in Cursor Cloud Agents. We upgraded the Cloud Agent environment so affected sessions require authentication for the relevant agent control channel....
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| cursor Product | < Fixedon03/31/2026 | Fixedon03/31/2026 |
Details and references
### Impact A vulnerability in browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled web content to connect from inside the agent container to an unauthenticated local agent endpoint. Successful exploitation allowed code execution within the affected Cloud Agent sandbox/session. An attacker could access files, repository contents, environment variables, and credentials available to that session. Cloud Agent sessions include GitHub App access tokens for repository operations. Exposure of these tokens allows read/write access to the associated repository, including code, pull requests, checks, and workflows, subject to the agent’s granted permissions. If customers configured additional secrets, such as cloud credentials, CI/CD tokens, or API keys, downstream impact to external systems could be higher depending on those credentials’ permissions. Exploitation requires: - A browser-capable Cloud Agent configuration. - An agent/browser flow that loaded attacker-controlled content. ### Patches The issue has been patched in Cursor Cloud Agents. We upgraded the Cloud Agent environment so affected sessions require authentication for the relevant agent control channel. No user action is required for Cursor-hosted Cloud Agents. ### CVSS CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L ### Reporter Credit to Arbër Salihi (@arber-salihi) Lead Product Security Engineer, Thomson Reuters
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-306
More Cursor advisories
All Cursor| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 14 | Sandbox escape via tampered Python virtual environments | High | 3.1.2 |
| Jul 14 | Sandbox escape via launching privileged containers | High | No fix yet |
| Jun 5 | Cursor Desktop sandbox escape via agent-controlled working directory | Critical | 3.0 |
| Jun 5 | Cursor Desktop sandbox escape via symlink and failed path canonicalization | Critical | 3.0 |
| May 21 | Cursor Desktop sandbox escape via Claude hook configuration | High8.5 | 3.0.0 |
| Mar 9 | Arbitrary Code Execution via Prompt Injection and Whitelist Bypass | High | 2.0 |