Registry/APM-0003
Case No.
APM-0003
Subject
Cursor
Filed
April 28, 2026
Severity
4 / 5 — SEVERE

Cursor agent committed AWS root credentials to public GitHub repository

Est. Damage ~$3k
Attribution Anonymous

Developer asked Cursor to commit and push a refactor. The agent did not verify the .gitignore was correctly excluding the .env file. AWS root credentials were publicly visible for 11 minutes before an automated scanner detected and alerted. Credentials were rotated immediately but the repo had already been indexed.