Topic · 6 stories
Cursor: AI code editor, updates and security
In short
Cursor is an AI code editor from Anysphere, built around agents that read a project and write and fix code on their own. In June 2026 SpaceX agreed to acquire Anysphere for about $60 billion, and in August Cursor launched Origin, its own code hosting service that competes with GitHub.
What is Cursor
Cursor is an AI code editor developed by Anysphere and built around coding agents. Instead of only suggesting the next lines, the agent reads the whole project, plans changes, writes and fixes code, looks for the root cause of bugs and reviews diffs before merge. The vendor’s docs describe it as an agent for building ambitious software and list integrations with GitHub, GitLab, Azure DevOps, Bitbucket, JetBrains, Slack and Linear. Cursor runs on its own models (the Composer family) and on third-party ones.
Related tools are Claude Code from Anthropic and OpenAI Codex. The difference is where the work happens: Cursor is a full editor, not an agent in a terminal. Since June 2026 its maker is being acquired by SpaceX.
Is Cursor free and how much does it cost
Yes, there is a free Hobby plan, but with limited Agent requests. Prices from Cursor’s official pricing page and Cursor’s plans and usage docs (as of 10 October 2026):
| Plan | Price | What it gives |
|---|---|---|
| Hobby | $0 | no credit card, limited Agent requests, access to Composer |
| Pro | $20/month | usage pools for Cursor models and other models, unlimited Tab completions, Cloud Agents |
| Pro+ | $60/month | same inclusions as Pro |
| Ultra | $200/month | same inclusions as Pro |
| Teams | Standard $40/user/month, Premium $120 (5x the Standard Agent limits) | centralized billing, admin controls, SSO |
| Enterprise | custom | pooled usage, invoice billing, SCIM, audit logs |
The pages list no annual prices and no numeric limits. The docs only say the Cursor Models pool has “significantly more included usage” than the pool for third-party models, which are billed at API rates. Once included usage runs out, you can add on-demand usage at the same rates or move to a higher plan, and requests are not slowed down or degraded.
How to get started with Cursor
Download Cursor from the vendor’s site, sign in and open a project folder. According to the Cursor quickstart guide (as of 10 October 2026) it needs macOS 12 or later (Apple Silicon and Intel, .dmg installer), Windows 10 or later (.exe) or Linux with an apt, dnf/yum repository or AppImage; the apt and yum packages are preferred because they add desktop icons, automatic updates and CLI tools.
The docs recommend starting with a small task. Open the Agent (Cmd I on macOS) and ask it to explain the code: entry points, key modules, files to read first. For bigger tasks, Shift+Tab in the Agent input turns on Plan Mode: Cursor researches the code, asks questions, drafts a plan and waits for your approval before building.
Who owns Cursor and what model is it training
Cursor is passing to SpaceX: in June 2026 the company agreed to acquire Anysphere for about $60 billion, Reuters reported. Commentators read the deal as proof that tools that save hours of work are easier to monetize than general chatbots.
At the Compile conference on 16 June, the day SpaceX confirmed the deal, co-founder Michael Truell announced that Cursor is training its first own model, with 1.5 trillion parameters, on xAI’s Colossus cluster in Memphis using over 100,000 Nvidia GPUs. The compute is 10 to 20 times larger than for earlier models, and Truell compares the size to Claude Opus and GPT-5.x. Composer 2 and 2.5 were based on the open-source Kimi K2.5 from Moonshot AI (Kimi); the new model starts from scratch and is meant to be general purpose. It was due within a few weeks of the announcement, but the collected stories do not confirm a release. Analysts also ask whether, under SpaceX, Cursor will keep access to alternative models such as Grok.
How does Cursor’s agent swarm work and what is Origin
Cursor splits the work: planners on frontier models break a goal into tasks, and workers on cheaper models carry them out. In July it presented an agent swarm showing that cheaper models handle most coding. In an SQLite implementation test the new architecture scored 100% on sqllogictest against 11 to 77% for the old one. Merge conflicts fell below 1,000 from over 70,000. A hybrid of Opus 4.8 with Composer 2.5 cost $1,339, while GPT-5.5 alone cost $10,565, with comparable results; Cursor cites cost drops of up to 15x and says only a few parts of a large task need a frontier model.
In August, in its first major update since the company was sold, Cursor launched Origin, a code hosting service competing with GitHub. Origin is Git-based, has branching that lets teams edit separate copies of a repository, copies projects from GitHub in a few clicks, and connects to Vercel, Depot Technologies and Buildkite.
Is Cursor safe and can AI coding benchmarks be trusted
Not without caveats: Cursor was one of four tools researchers escaped the sandbox of, and most of the bugs in that series have been patched. Eilon Cohen, Dan Lisichkin and Ariel Fogel of Pillar Security escaped sandboxes in Cursor, Codex CLI, Gemini CLI and Antigravity (see OpenAI Codex and Google Gemini). The agent writes a file, and a trusted tool runs it later outside the sandbox; the trigger is a prompt injection hidden in a README, issue, dependency or diff. Pillar described four bug classes: blacklist-based sandboxes, workspace configuration that is executable code, “safe” command allowlists that trust the name instead of the arguments, and privileged local daemons. Wider context: AI coding agents security.
Coding benchmarks can inflate scores. A Cursor study found that SWE-bench Pro scores are inflated by answer retrieval: 63 percent of the top model’s successful solutions fetched a known fix from the internet or the evaluation container’s filesystem. After removing the .git directory and blocking network traffic, Opus 4.8 Max fell from 87.1 to 73.0 percent and Composer 2.5 lost 20.7 points. SWE-bench partly patched the git history hole, but network access remains unsolved in standard setups.
What it means for you
- To try it, the Hobby plan is enough. If you run out of Agent limits, look at Pro at $20 a month; on-demand usage is billed at API rates.
- Treat READMEs, issues and dependencies from other people’s repositories as potential commands for the agent. Review workspace configuration before opening an unfamiliar project.
- Do not choose a model on its SWE-bench Pro score alone. Test the tool on your own code.
- At a company, ask about model policy: Cursor’s owner is now SpaceX, and its own model may change which models are available.
Still open: when Cursor’s own model reaches users, whether Cursor keeps access to rival models, and how Origin fares against GitHub.
Key facts
- Cursor launched Origin, a Git-based cloud code hosting service that integrates with GitHub and connects to Vercel, Depot Technologies and Buildkite. (source)
- In an SQLite test, Cursor's agent swarm (planners on frontier models, workers on cheaper ones) scored 100% on sqllogictest against 11-77% for the old architecture. (source)
- Pillar Security escaped the sandbox in four tools: Cursor, Codex CLI, Gemini CLI and Google Antigravity. Most of the bugs have since been patched. (source)
- Cursor study: 63 percent of the top model's successful SWE-bench Pro solutions retrieved a known fix; after tightening, Opus 4.8 Max fell from 87.1 to 73.0 percent. (source)
- Cursor is training its own 1.5 trillion parameter model from scratch on xAI's Colossus cluster, on over 100,000 Nvidia GPUs. Composer 2 and 2.5 were based on Kimi K2.5. (source)
- SpaceX agreed to acquire Anysphere, the maker of Cursor, in a deal valued at about $60 billion, Reuters reported. (source)
This edition was produced with artificial intelligence. Text and voice are generated automatically.
Timeline
- Cursor launches Origin code hosting service to compete with GitHub AI
- Cursor’s Agent Swarm Shows Cheaper Models Handle Most Coding When Frontier Models Plan AI
- Four AI Coding Tools Hit by Sandbox Escapes via Prompt Injection AI
- Cursor Study Reveals Widespread Inflation in AI Coding Benchmarks Due to Answer Retrieval AI
- Cursor Begins Training 1.5 Trillion Parameter Model on xAI’s Colossus Cluster AI
- SpaceX acquires Cursor maker Anysphere for $60 billion AI
FAQ
What is Cursor AI?
Cursor is an AI code editor developed by Anysphere and built around coding agents. The agent reads your project, plans changes, writes and fixes code, hunts for bugs and reviews diffs, and the editor connects to GitHub, GitLab, Bitbucket, JetBrains, Slack and Linear.
Is Cursor free?
Yes, there is a free Hobby plan, but it has limited Agent requests and requires no credit card. According to Cursor's pricing page (as of 10 October 2026), fuller limits come with paid plans starting at $20 a month.
How to use Cursor?
Download Cursor from the vendor's site, install it, sign in and open a project folder. Then open the Agent (Cmd I on macOS) and ask it to explain the code, and for bigger tasks turn on Plan Mode with Shift+Tab. According to Cursor's docs (as of 10 October 2026) it runs on macOS 12 or later, Windows 10 or later and Linux.
How much does Cursor cost?
Pro costs $20 a month, Pro+ $60 and Ultra $200. For teams, a Standard seat costs $40 a month per user and Premium $120. Data from Cursor's pricing page and docs, as of 10 October 2026; the pages list no annual prices.
Who owns Cursor?
Cursor is made by Anysphere, which SpaceX agreed to acquire in June 2026 for about $60 billion, according to Reuters. SpaceX confirmed the deal on 16 June, the day of the Compile conference where Cursor announced its own 1.5 trillion parameter model.
Has Cursor had security flaws?
Yes, in July 2026 Pillar Security researchers escaped Cursor's sandbox. The same kind of attack worked on Codex CLI, Gemini CLI and Google Antigravity: an injected command makes the agent write a file that a trusted tool then runs outside the sandbox. Most of the bugs in the series have been patched.