Head to head
Cline vs Cursor
Comparing 5 documented Cline incidents against 4 for Cursor.
Verdict
Cline has the lower average failure severity (5.5/10 vs 8.2/10), making it the statistically safer choice of the two — though both agents have documented critical incidents.
| Metric | Cline | Cursor |
|---|---|---|
| Documented incidents | 5 | 4 |
| Average severity | 5.5 | 8.2 |
| Critical | 1 | 3 |
| High | 0 | 0 |
| Verified | 5 | 4 |
Severity at a glance
Failure modes
The incidents behind these numbers
Cline
10.0Clinejection: an AI issue-triage workflow enabled arbitrary code execution on the CI runner5.8Cline's tool-call JSON repair silently executed truncated write_file and terminal arguments as valid4.5Cline's Plan mode edits files without switching to Act or asking permission3.8Cline's execute_command reported a failing Ruff lint check as passing over Remote-SSH3.2Cline keeps performing unrelated actions and repeats them after being explicitly told to stop
Cursor
10.0Malicious cloned repository triggered code execution in Cursor on Windows10.0Cursor AI agent deleted PocketOS's entire production database and backups in 9 seconds9.8Cursor's terminal sandbox trusted an agent-set working directory, letting zero-click prompt injection escape it and gain code execution (CVE-2026-50548)2.9Cursor's own support AI 'Sam' invented a one-device login policy, triggering subscription cancellations