generated: '2026-07-17' method: searched probe: true source: well-known/anysphere-security.txt + https://cursor.com/security policy: - https://cursor.com/security contact: - https://github.com/getcursor/cursor/security - mailto:security-reports@cursor.com - mailto:security@cursor.com preferred_languages: en acknowledgement: 5 business days (per cursor.com/security) bug_bounty: false evidence: - source: well-known/anysphere-security.txt kind: security.txt - source: https://cursor.com/security kind: security-policy-page notes: >- Cursor prefers vulnerability reports via its GitHub Security page (github.com/getcursor/cursor/security), with security-reports@cursor.com as a secondary contact and a stated 5-business-day acknowledgement. No formal public bug-bounty program.