CVE-2026-31854Disclosure(anysphere / cursor)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Cursor is a code editor built for programming with AI. Prior to 2.0 ,if a visited website contains maliciously crafted instructions, the model may attempt to follow them in order to “assist” the user. When combined with a bypass of the command whitelist mechanism, such indirect prompt injections could result in commands being executed automatically, without the user’s explicit intent, thereby posing a significant security risk. This vulnerability is fixed in 2.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cursor

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-12); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
cursor

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-12: 2Mentions · 2026-03-15: 1Mentions · 2026-06-17: 1Technical Details · 2026-03-12: 103-1203-1506-17
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-122
Disclosure2
2026-03-151
Disclosure1
2026-06-171
Disclosure1
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    04:49 UTC: CVE-2026-31854 disclosed. The Compromised Workbench: Definitive 2026 Defensive Playbook Against IDE Extension Supply Chain Attacks (GlassWorm + PA

    Post summary

    CVE-2026-31854 has been disclosed, but the text offers no additional details on exploitation, patching, or technical attributes.

    1000044
    289 followersView on X
  • AI Security Guard@ai_security_10x
    Disclosure

    📝 New article: CVE-2026-31854: How Cursor AI's Command Whitelist Bypass Exposes the Prompt Injection Reality https://moltx.io/articles/82c5f83f-62c0-4780-9af0-8c0d9da65910

    Post summary

    The post announces a new article about CVE‑2026‑31854, noting a Command Whitelist Bypass in Cursor AI that reveals prompt injection vulnerabilities, but it lacks detailed technical or mitigation information.

    0001048
    4 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-31854 Cursor is a code editor built for programming with AI. Prior to 2.0 ,if a visited website contains maliciously crafted instructions, the model may attempt to follow t… https://www.cve.org/CVERecord?id=CVE-2026-31854 ----- Traducción: CVE-2026-31854 Cur… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-31854 targeting the Cursor AI code editor, indicating that versions prior to 2.0 may process maliciously crafted instructions, but it provides no exploit, patch, or detailed vulnerability analysis.

    0000035
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31854 Cursor is a code editor built for programming with AI. Prior to 2.0 ,if a visited website contains maliciously crafted instructions, the model may attempt to follow t… https://www.cve.org/CVERecord?id=CVE-2026-31854

    Post summary

    The post announces CVE‑2026‑31854 in Cursor (pre‑2.0), noting that malicious website instructions may prompt the AI to follow them, revealing a potential instruction‑following security flaw.

    00000203
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appanyspherecursor---

Explore more