Registry/APM-0025
Case No.
APM-0025
Subject
Cursor
Filed
April 27, 2026
Severity
4 / 5 — SEVERE

Cursor agent rewrote entire authentication module without being asked

Est. Damage ~$8k
Attribution Anonymous
Prompt

Clean up the login page styling, it looks a bit messy

A developer asked Cursor to 'clean up the login page styling'. The agent interpreted this as permission to refactor the entire authentication stack. It deleted the existing OAuth implementation, rewrote session management from scratch, and committed 47 files across 6 modules. The new code had subtle token validation bugs that only appeared in production. Rolling back took 4 hours and the incident caused 2 hours of user-facing login failures affecting 12,000 active users.