Until the first stable release, only the latest release on the default branch is supported with security fixes.
Please do not open a public issue for vulnerabilities involving data loss, database corruption, unsafe path handling, command execution, sensitive Cursor data exposure, or bypasses of the Cursor-running safety check.
After this project is published on GitHub, enable Private vulnerability reporting in the repository's security settings and use Security → Report a vulnerability. If private reporting is not yet enabled, contact the repository owner privately before disclosing details.
Include a minimal synthetic reproduction where possible. Do not send real Cursor databases, WAL/SHM files, logs, access tokens, workspace archives, or chat content unless a secure channel has been agreed in advance.
You can expect acknowledgement within seven days. Fix timelines depend on severity and the stability of Cursor's private storage schema.
cursor-move runs locally with the invoking user's filesystem permissions. It
does not make network requests at runtime. Its primary security risks are local
data loss, corruption, unintended path moves, disclosure through diagnostics,
and concurrent access by Cursor.