2026 Cursor (Anysphere) — cross-account dashboard / BugBot data mixing for users sharing one GitHub identity
Data compromised
Account metadata and usage analytics visible across organizational boundaries; potential mapping of personal repositories to a team BugBot context per reporter
Technical writeup
In early March 2026 a user report on Cursor’s community forum described a serious account-boundary failure: a personal Cursor account and a separate work Cursor account (distinct emails), both linked to the same GitHub user, caused personal usage analytics and the personal email address to appear inside the team dashboard leaderboard, and BugBot behavior suggested repositories were being associated with the wrong Cursor organization. Cursor staff acknowledged the report and routed it to security, characterizing the behavior as unintended when two accounts share a GitHub linkage.
Root cause
Product logic linking multiple Cursor tenants to one GitHub identity without strict analytics/BugBot isolation