Head to head
Cursor vs GitHub Copilot
Comparing 4 documented Cursor incidents against 5 for GitHub Copilot.
Verdict
Cursor has the lower average failure severity (8.2/10 vs 8.2/10), making it the statistically safer choice of the two — though both agents have documented critical incidents.
| Metric | Cursor | GitHub Copilot |
|---|---|---|
| Documented incidents | 4 | 5 |
| Average severity | 8.2 | 8.2 |
| Critical | 3 | 3 |
| High | 0 | 1 |
| Verified | 4 | 5 |
Severity at a glance
Cursor
8.2
high
GitHub Copilot
8.2
high
Failure modes
CursorDistribution of failure modes across all documented incidents.
GitHub CopilotDistribution of failure modes across all documented incidents.
The incidents behind these numbers
Cursor
10.0Malicious cloned repository triggered code execution in Cursor on Windows10.0Cursor AI agent deleted PocketOS's entire production database and backups in 9 seconds9.8Cursor's terminal sandbox trusted an agent-set working directory, letting zero-click prompt injection escape it and gain code execution (CVE-2026-50548)2.9Cursor's own support AI 'Sam' invented a one-device login policy, triggering subscription cancellations
GitHub Copilot
10.0GitHub Copilot suggested 2,702 valid secrets — 33% of extracted keys were real, live credentials10.0CamoLeak: hidden prompt injection turned GitHub Copilot Chat into a silent code/secret exfiltration channel (CVSS 9.6)10.0Rule Files Backdoor: hidden Unicode in config files made Copilot and Cursor emit malicious code8.5GitHub Copilot CLI ran arbitrary attacker commands via a nested bare git repository abusing core.fsmonitor (CVE-2026-45033)2.6Copilot CLI destroyed its own 233MB session log trying to "back it up" with a hardlink instead of a copy