Cursor Review 2026: A $60B Agentic Platform Six Weeks From Losing OpenAI's Models

Sources

Cursor stopped being an IDE a while ago. The product you can buy in October 2026 is a full agentic delivery stack: an editor, a terminal agent CLI, cloud agents that run on rented sandboxes, self-hosted worker pools you can run inside your own network, a GitHub alternative called Origin, coordinator-driven "Projects" that delegate to fleets of subagents, and two shipping bots — Rollouts and Security Review — that watch your deploys and your pull requests. It also now owns a frontier model: Grok 4.7, trained under a SpaceX partnership, is Cursor's in-house default for long-horizon agent work.

Two events make this review due now rather than quarterly. First, OpenAI is cutting Cursor off — OpenAI models go dark in Cursor on November 12, 2026, 35 days from this writing, because OpenAI says it "cannot be confident that SpaceX will use our technology within our terms of service" after Musk-owned companies broke contracts before. Second, the September–October feature run (Projects, self-hosted machines, Rollouts, Security Review, remote control of local agents from an iOS app) shows Cursor building toward platform lock-in, not just editor market share — which changes the buyer's calculus from "which editor do my engineers like" to "how much of my delivery pipeline do I want dependent on one vendor that just demonstrated its upstream model supply can be switched off by a rival."

We installed the real Cursor Agent CLI (version 2026.10.01-e373342) on a Linux box, ran its unauthenticated surface end to end, read its installer and worker tooling, and verified every pricing, model, and security claim against Cursor's own published pages. The verdict: Cursor is the most complete agentic coding platform on the market and simultaneously the riskiest default to standardize on — because its guardrails are explicitly best-effort, its cost dashboard got less transparent in August, and its model lineup now lives at the intersection of a $60B acquisition and an open corporate feud.

Executive Scorecard

DimensionScoreWhy
ReliabilityBCloud agents, Projects, and the CLI are all shipping and coherent, but the platform just proved its model supply chain is breakable by a third party (OpenAI shutoff, Nov 12). Self-hosted workers and Bring-Your-Own-Sandbox options offset this for teams that use them.
DXAThe widest agent surface in the market: editor, CLI, cloud, self-hosted pools, mobile remote control, headless CI mode. The VS Code migration path is still the lowest-friction onboarding in the category.
CostCComposer 2.5 at $0.50/$2.50 per million tokens is genuinely cheap, but the usage dashboard dropped dollar amounts for token counts in July 2026 and the CSV export lost cost data — metering your own spend now takes external tooling.
SecurityC-SOC 2 Type II, ISO 27001, and privacy mode are real, but Cursor's own docs call its guardrails "best-effort rather than a hard security boundary," workspace trust ships disabled, and a planted-git.exe arbitrary-code-execution 0day reported in December 2025 was still unfixed across 197+ releases as of September 2026.

What Cursor Actually Is Now

The surface area is the story. A year ago "Cursor review" meant "VS Code fork with a chat pane." Today the product spans:

                    CURSOR PLATFORM SURFACE (Oct 2026)
                    ===================================

  you ──┬── Editor (VS Code fork) ── Agent (Cmd+I) ── Plan/Ask modes
        ├── CLI: `agent` binary ──┬── interactive TUI
        │                          ├── -p print mode (scripts, CI)
        │                          ├── persist (survives disconnect)
        │                          └── worker --pool (self-hosted worker)
        ├── iOS app ── remote control ──> local agents on your machine
        └── Dashboard ── Automations tab
                          ├── Bugbot        (PR code review)
                          ├── Rollouts      (deploy health per env)
                          └── Security Review (exploitable bugs per PR)

  agents run on ──┬── your laptop (local agent)
                  ├── Cursor cloud (default)
                  ├── BYO sandbox: Lambda, Cloudflare, Modal, Vercel,
                  │                E2B, Coder, Daytona, Namespace
                  └── self-hosted pool (your network, your secrets)
                                    │
                                    └── k8s-ready: /healthz /readyz
                                        /metrics, idle release timer

  model layer ──┬── Cursor Models pool: Grok 4.7 / 4.6 / 4.5, Composer 2.5
                └── Other Models pool: Anthropic, Google, ... OpenAI*
                                                       (*until Nov 12, 2026)

  SCM layer ──┬── GitHub / GitLab / Bitbucket / Azure DevOps integrations
              └── Origin (Cursor's own repos, no third-party SCM required)

The strategic read: every one of those bullets is a hook deeper into your delivery pipeline. That is not automatically bad — integration is the value proposition — but it means an evaluation of "Cursor the editor" undersells what you are actually buying, and an evaluation of "Cursor the platform" has to price the exit.

The November 12 Deadline

On August 28, 2026, OpenAI published a short, unusually direct statement: it notified SpaceX that it intends to wind down the contract providing OpenAI models to Cursor, with a proposed shutoff date of November 12, 2026 — the maximum contractual notice after the change-of-control clause triggered by the $60B acquisition. OpenAI's stated reason: "we cannot be confident that SpaceX will use our technology within our terms of service, based on our experience with Elon Musk's companies violating contracts," citing both the Twitter-era contract breaches and Musk's under-oath admission that xAI violated OpenAI's terms.

For a buyer, the interesting part is not the feud — it is what the shutoff does to model choice inside Cursor. Today the model picker still lists GPT-5.6 variants; after November 12, it will not. Anthropic's Claude line (Sonnet 5.5, Opus 5.5, Fable 5.1, Haiku 5.5), Google's Gemini 3.x, and Cursor's own Grok/Composer remain. Cursor's answer to the shutoff was to build the alternative in-house: Grok 4.7 shipped September 21, 2026, "at the same price and speed as Grok 4.6," with a 256k standard window and 500k long-context variant, and a SpaceX model-training partnership behind it. On CursorBench 4.0 Cursor reports 46.3% at extra-high effort.

The usage-pool structure is where the economics actually live. Every paid plan now splits into two pools: Cursor Models (Grok 4.7/4.6/4.5 and Composer 2.5 — "significantly more included usage") and Other Models (third-party models "charged at the model's API price," a smaller included allowance with overage billing). Cursor does not publish the pool sizes on the marketing page — you see them in your dashboard — but the direction is explicit: the cheap, large pool pushes you toward Cursor-owned models, and the expensive, small pool meters you toward API-rate pricing when you leave the in-house lineup.

Model (per million tokens)InputCache ReadOutput10M output tokensPool
Composer 2.5$0.50$0.20$2.50$25Cursor Models
Grok 4.7$2.00$0.50$6.00$60Cursor Models
Grok 4.7 (Fast)$4.00$1.00$12.00$120Cursor Models
Grok 4.7 500k$4.00$1.00$12.00$120Cursor Models
Claude Sonnet 5.5$2.00$0.10$10.00$100Other Models
Claude Opus 5.5$4.00$0.20$20.00$200Other Models
Claude Fable 5.1$10.00$0.25$50.00$500Other Models
Claude Haiku 5.5$0.10$0.01$0.50$5Other Models

Rates from cursor.com/docs/models, verified October 8, 2026. Grok 4.7 output is 2.4× the price of Composer 2.5 output; Claude Opus 5.5 output is 3.3× Grok 4.7. The "10M output tokens" column is output-side only — a labeled unit comparison, not a total-cost estimate, since real agent workloads mix input, cache, and output at very different ratios.

Plan prices themselves are simple: Hobby free, Individual $20/month, Teams $40/user/month (Standard or Premium), Enterprise custom with pooled usage, SCIM, invoice billing, and repo/model/MCP access controls. There is no published Pro+/Ultra price on the live pricing page cards beyond the $20/$40 pair — the higher individual tiers are pitched by usage size in the FAQ rather than a price table, which means the real cost of an agent-heavy individual workflow is discoverable only inside the product.

Hands-On: The Agent CLI

The CLI is the surface platform engineers should actually evaluate first — it is the one that fits existing terminal-driven workflows and CI. We installed it on a clean Linux box with the documented one-liner:

$ curl https://cursor.com/install -fsS | bash
▸ Detected linux/x64
✓ Package downloaded and extracted
✓ Symlink created

✨ Installation Complete!

$ export PATH="$HOME/.local/bin:$PATH"
$ agent --version
2026.10.01-e373342

What the installer actually does is worth knowing before you pipe it to a shell: it downloads agent-cli-package.tar.gz from downloads.cursor.com/lab/<version>/<os>/<arch>/, extracts into ~/.local/share/cursor-agent/versions/, and symlinks both agent and cursor-agent into ~/.local/bin. Note the /lab/ path segment — the "CLI" is versioned as a lab package. One more discovery: the old cursor-agent npm package is a dead end, last published January 2025 at 1.0.3 with zero updates since; anything that installs Cursor's CLI from npm in 2026 is installing a two-year-old artifact. The current binary ships only from cursor.com.

Every subcommand requires authentication — agent --list-models, agent -p, even agent status fail cleanly without a login:

$ agent --list-models
Error: Authentication required. Run 'agent login', pass --api-key/--auth-token,
or set CURSOR_API_KEY/CURSOR_AUTH_TOKEN.

$ agent -p "say hi"
Error: Authentication required. Please run 'agent login' first, or set
CURSOR_API_KEY environment variable.

$ agent about
About Cursor CLI
CLI Version         2026.10.01-e373342
Latest              2026.10.01-e373342 (up to date)
Model               Auto
Subscription Tier   Unknown
OS                  linux (x64)
Shell               bash
User Email          Not logged in

The flag surface tells you the operational model of the product. The three approval flags are the ones to read carefully:

--mode plan gives a read-only planner, --mode ask a read-only Q&A mode, --resume/--continue reattach to sessions, -w/--worktree runs the agent in an isolated git worktree under ~/.cursor/worktrees/, and --output-format json|stream-json makes print mode scriptable. There is also a persist subcommand for sessions that survive terminal disconnects and bedrock for configuring AWS Bedrock usage — a nod to enterprises that refuse direct third-party model egress.

The subcommand that matters most for platform teams is worker:

$ agent worker --help
Run a self-hosted Cloud Agent worker that connects to Cursor and executes
agent tool calls on this machine. Without --pool it is a personal My
Machines worker (no Enterprise plan needed); with --pool it joins a team
Self-Hosted Pool (Enterprise plan + service account API key).

  --auth-token-file <path>   worker auth token, operator-managed Secret mounts
  --worker-dir <path>        workspace root exposed to agents (repeatable)
  --management-addr <addr>   HTTP server: GET /healthz, /readyz (Kubernetes
                             probes) and /metrics (Prometheus text scrape)
  --label key=value          worker labels (repeatable)
  --idle-release-timeout <seconds>  seconds the worker stays connected after
                             going idle before exit; default 3600; 0 disables

That is a well-designed worker contract: Kubernetes liveness/readiness probes, a Prometheus scrape endpoint, Secret-mount token files, label-based routing, and a clean idle-exit (exit code 0) designed for a supervisor to restart. For an enterprise that will not let third-party agents touch code outside its network, this — plus the pools feature (named queues, capacity that grows with demand, hibernation for idle machines with reconnect-window restore) — is the strongest argument for Cursor over editor-attached competitors: you can run the entire execution plane in your own infra and let Cursor coordinate.

The iOS remote-control feature shipped October 6 is the same idea pointed at individuals: your local agents keep running on your machine, and the app connects to them — the docs are explicit that the computer must stay on and online, and that the feature is on by default for everyone except Enterprise orgs, where an admin opt-in is required. Read that default again: a phone-app tunnel into the machine running your dev agents is opt-out, not opt-in. For BYOD-heavy orgs without an Enterprise plan, that is a conversation to have with security before rollout, not after.

Guardrails: Read the Fine Print Before You Trust the Agent

Cursor's agent security documentation deserves credit for one thing: it is more honest than most vendor security pages. The key sentences, verbatim from the agent security docs:

That last cluster is the real risk model for agentic coding: an agent that writes config files immediately to disk, executes code on save via auto-reload, and reaches network endpoints — with guardrails the vendor itself classifies as best-effort. .cursorignore exists for file-level exclusion, MCP connections require per-tool approval, and privacy mode contractually keeps code out of training — those are real controls. But the honest summary is: Cursor's default posture trusts the workspace until you harden it, and the hardening is a collection of speed bumps, not a boundary.

Then there is the 0day. Mindgard disclosed in September 2026 — after reporting it privately since December 15, 2025 — that Cursor on Windows executes a planted git.exe found in the opened repository's root, with no interaction, no prompt, and no warning, repeatedly on a cadence. That is arbitrary code execution from "open a malicious repo." Mindgard's frustration is dated and specific: the issue was still present in the latest tested version after "more than six months and 197+ new versions." Cursor's scale makes the exposure non-trivial — the disclosure cites 7M+ active users and 50K+ companies. The mitigating reality: you need to open an attacker-controlled repo on Windows. The damning reality: a vendor that ships a self-updating binary 197 times in six months left a one-click RCE in the loader path the whole time. If you run Cursor on Windows and open third-party repos, treat this as live and assume the fix when it lands needs verification on your fleet; cloned-repo provenance is now a security input.

Certifications are real and current — SOC 2 Type II, ISO 27001:2022, ISO 42001:2023, AIUC-1, at-least-annual third-party penetration testing, a published subprocessor list on the trust portal, and an explicit no-China-infrastructure statement. The corporate security posture is not the weak point; the client runtime is.

The Cost-Opacity Problem

On July 31, 2026, users noticed the usage page had swapped dollar amounts for token counts, and the CSV export lost its cost columns. The forum thread that followed is a masterclass in quiet metering changes: long-time customers describing the dollar view as the only way they kept tabs on daily spend, with no revert setting and no explanation in the changelog. The HN thread (337 points) had a more pointed subtext — several multi-year paying users said the change tracked with a general post-acquisition pattern of usage opacity, and more than a few said they had already moved their writing to Claude Code or Codex and only kept Cursor for review.

Why this matters more than a normal SaaS dashboard gripe: agent workloads are the highest-variance spend category in the dev-tool budget. A single runaway agent loop can burn through a pool in hours. A dashboard that shows "tokens consumed" against a pool whose dollar conversion depends on which of two pools and which model inside it fired — on a product where the cheap pool is Cursor-owned models — is a dashboard that makes the vendor's cheapest path look free and your overage invisible until the invoice. The admin dashboard on Teams retains usage analytics, and Enterprise gets pooled usage and the AI code tracking API, so the enterprise tier can rebuild the meter externally. Everyone else should plan to export and recompute, because the product no longer does that arithmetic for you.

Critical Failure Modes

Verdict: Buy for the Execution Plane, Not the Model Story

Cursor in October 2026 is two products wearing one brand. The first is the best-integrated agentic execution platform on the market: editor-to-CLI-to-cloud-to-self-hosted continuity, Kubernetes-grade worker tooling, BYO-sandbox flexibility, and delivery bots that touch the part of the pipeline where money actually leaks (deploy verification, PR security). If you evaluate that product on its own merits — especially the self-hosted worker pools, which let you keep code and secrets inside your network — it is genuinely strong, and no competitor currently matches the span.

The second product is a model-subscription business whose headline asset is a 35-day-old model (Grok 4.7) from a company whose upstream rival just demonstrated the ability to cut off a model line by decree, whose usage pricing nudges users toward in-house models via pool asymmetry, and whose cost transparency regressed this quarter. The Nov 12 shutoff is not a reason to avoid Cursor — Anthropic and Google models remain, and Grok 4.7's published rates are competitive ($2/$6 against Sonnet 5.5's $2/$10, with a 4× cache-read discount). It is a reason to treat every model subscription inside an agent platform as replaceable, and to keep your prompts, rules, and evals portable enough to survive a forced model migration.

Who Should Skip This

References & Further Reading