Cursor Review 2026: A $60B Agentic Platform Six Weeks From Losing OpenAI's Models
Sources
- Cursor pricing (verified 2026-10-08)
- Cursor changelog — Remote control, Rollouts, Projects (Sep-Oct 2026)
- Cursor models and pricing — Grok 4.7, Composer 2.5, usage pools
- Cursor agent security defaults — guardrails are best-effort
- Cursor CLI overview and install
- Grok 4.7 announcement and SpaceX training partnership
- OpenAI: Our decision on Cursor following its acquisition by SpaceX (Aug 28, 2026)
- Mindgard: Cursor 0day — planted git.exe executes with no interaction
- Cursor forum: usage page switched from dollars to token amounts (Jul 31, 2026)
- HN discussion: OpenAI's decision on Cursor (852 points)
- cursor-agent on npm (stale 1.0.3, Jan 2025 — current CLI ships from cursor.com)
Cursor stopped being an IDE a while ago. The product you can buy in October 2026 is a full agentic delivery stack: an editor, a terminal agent CLI, cloud agents that run on rented sandboxes, self-hosted worker pools you can run inside your own network, a GitHub alternative called Origin, coordinator-driven "Projects" that delegate to fleets of subagents, and two shipping bots — Rollouts and Security Review — that watch your deploys and your pull requests. It also now owns a frontier model: Grok 4.7, trained under a SpaceX partnership, is Cursor's in-house default for long-horizon agent work.
Two events make this review due now rather than quarterly. First, OpenAI is cutting Cursor off — OpenAI models go dark in Cursor on November 12, 2026, 35 days from this writing, because OpenAI says it "cannot be confident that SpaceX will use our technology within our terms of service" after Musk-owned companies broke contracts before. Second, the September–October feature run (Projects, self-hosted machines, Rollouts, Security Review, remote control of local agents from an iOS app) shows Cursor building toward platform lock-in, not just editor market share — which changes the buyer's calculus from "which editor do my engineers like" to "how much of my delivery pipeline do I want dependent on one vendor that just demonstrated its upstream model supply can be switched off by a rival."
We installed the real Cursor Agent CLI (version 2026.10.01-e373342) on a Linux box, ran its unauthenticated surface end to end, read its installer and worker tooling, and verified every pricing, model, and security claim against Cursor's own published pages. The verdict: Cursor is the most complete agentic coding platform on the market and simultaneously the riskiest default to standardize on — because its guardrails are explicitly best-effort, its cost dashboard got less transparent in August, and its model lineup now lives at the intersection of a $60B acquisition and an open corporate feud.
Executive Scorecard
| Dimension | Score | Why |
|---|---|---|
| Reliability | B | Cloud agents, Projects, and the CLI are all shipping and coherent, but the platform just proved its model supply chain is breakable by a third party (OpenAI shutoff, Nov 12). Self-hosted workers and Bring-Your-Own-Sandbox options offset this for teams that use them. |
| DX | A | The widest agent surface in the market: editor, CLI, cloud, self-hosted pools, mobile remote control, headless CI mode. The VS Code migration path is still the lowest-friction onboarding in the category. |
| Cost | C | Composer 2.5 at $0.50/$2.50 per million tokens is genuinely cheap, but the usage dashboard dropped dollar amounts for token counts in July 2026 and the CSV export lost cost data — metering your own spend now takes external tooling. |
| Security | C- | SOC 2 Type II, ISO 27001, and privacy mode are real, but Cursor's own docs call its guardrails "best-effort rather than a hard security boundary," workspace trust ships disabled, and a planted-git.exe arbitrary-code-execution 0day reported in December 2025 was still unfixed across 197+ releases as of September 2026. |
What Cursor Actually Is Now
The surface area is the story. A year ago "Cursor review" meant "VS Code fork with a chat pane." Today the product spans:
- The editor and Agent — the original surface; agents with full tool access, Plan/Ask modes, design mode, MCP support, rules, skills, subagents, and hooks.
- Projects (Sep 10, 2026) — coordinator agents that plan work, delegate to thousands of parallel subagents, keep months-scale shared context that syncs across cloud and local machines, and can subscribe to Slack channels, schedules, or your PRs.
- Cloud agents — run on Cursor's cloud or on sandboxes you already pay for (AWS Lambda, Cloudflare, Modal, Vercel, E2B, Coder, Daytona, Namespace), with live port-forwarded browser previews.
- Self-hosted machines (Sep 2, 2026) — team pools of workers inside your own network; pools are named queues, scale with demand, hibernate idle machines, and restore within a reconnect window.
- Origin — Cursor's own SCM, so cloud agents no longer need GitHub to start; repos can be mirrored from GitHub or built from scratch.
- Shipping bots — Bugbot (code review), Rollouts (deploy health monitoring per environment), Security Review (exploitable-bug review on every PR), and PR routing/approval automations.
- The CLI — a standalone
agentbinary with interactive, headless/CI, and shell modes, plus a worker mode for self-hosted pools. - Grok 4.7 and Composer 2.5 — Cursor's own models, with a "Cursor Models" usage pool that is much larger than the third-party "Other Models" pool on every plan.
CURSOR PLATFORM SURFACE (Oct 2026)
===================================
you ──┬── Editor (VS Code fork) ── Agent (Cmd+I) ── Plan/Ask modes
├── CLI: `agent` binary ──┬── interactive TUI
│ ├── -p print mode (scripts, CI)
│ ├── persist (survives disconnect)
│ └── worker --pool (self-hosted worker)
├── iOS app ── remote control ──> local agents on your machine
└── Dashboard ── Automations tab
├── Bugbot (PR code review)
├── Rollouts (deploy health per env)
└── Security Review (exploitable bugs per PR)
agents run on ──┬── your laptop (local agent)
├── Cursor cloud (default)
├── BYO sandbox: Lambda, Cloudflare, Modal, Vercel,
│ E2B, Coder, Daytona, Namespace
└── self-hosted pool (your network, your secrets)
│
└── k8s-ready: /healthz /readyz
/metrics, idle release timer
model layer ──┬── Cursor Models pool: Grok 4.7 / 4.6 / 4.5, Composer 2.5
└── Other Models pool: Anthropic, Google, ... OpenAI*
(*until Nov 12, 2026)
SCM layer ──┬── GitHub / GitLab / Bitbucket / Azure DevOps integrations
└── Origin (Cursor's own repos, no third-party SCM required)The strategic read: every one of those bullets is a hook deeper into your delivery pipeline. That is not automatically bad — integration is the value proposition — but it means an evaluation of "Cursor the editor" undersells what you are actually buying, and an evaluation of "Cursor the platform" has to price the exit.
The November 12 Deadline
On August 28, 2026, OpenAI published a short, unusually direct statement: it notified SpaceX that it intends to wind down the contract providing OpenAI models to Cursor, with a proposed shutoff date of November 12, 2026 — the maximum contractual notice after the change-of-control clause triggered by the $60B acquisition. OpenAI's stated reason: "we cannot be confident that SpaceX will use our technology within our terms of service, based on our experience with Elon Musk's companies violating contracts," citing both the Twitter-era contract breaches and Musk's under-oath admission that xAI violated OpenAI's terms.
For a buyer, the interesting part is not the feud — it is what the shutoff does to model choice inside Cursor. Today the model picker still lists GPT-5.6 variants; after November 12, it will not. Anthropic's Claude line (Sonnet 5.5, Opus 5.5, Fable 5.1, Haiku 5.5), Google's Gemini 3.x, and Cursor's own Grok/Composer remain. Cursor's answer to the shutoff was to build the alternative in-house: Grok 4.7 shipped September 21, 2026, "at the same price and speed as Grok 4.6," with a 256k standard window and 500k long-context variant, and a SpaceX model-training partnership behind it. On CursorBench 4.0 Cursor reports 46.3% at extra-high effort.
The usage-pool structure is where the economics actually live. Every paid plan now splits into two pools: Cursor Models (Grok 4.7/4.6/4.5 and Composer 2.5 — "significantly more included usage") and Other Models (third-party models "charged at the model's API price," a smaller included allowance with overage billing). Cursor does not publish the pool sizes on the marketing page — you see them in your dashboard — but the direction is explicit: the cheap, large pool pushes you toward Cursor-owned models, and the expensive, small pool meters you toward API-rate pricing when you leave the in-house lineup.
| Model (per million tokens) | Input | Cache Read | Output | 10M output tokens | Pool |
|---|---|---|---|---|---|
| Composer 2.5 | $0.50 | $0.20 | $2.50 | $25 | Cursor Models |
| Grok 4.7 | $2.00 | $0.50 | $6.00 | $60 | Cursor Models |
| Grok 4.7 (Fast) | $4.00 | $1.00 | $12.00 | $120 | Cursor Models |
| Grok 4.7 500k | $4.00 | $1.00 | $12.00 | $120 | Cursor Models |
| Claude Sonnet 5.5 | $2.00 | $0.10 | $10.00 | $100 | Other Models |
| Claude Opus 5.5 | $4.00 | $0.20 | $20.00 | $200 | Other Models |
| Claude Fable 5.1 | $10.00 | $0.25 | $50.00 | $500 | Other Models |
| Claude Haiku 5.5 | $0.10 | $0.01 | $0.50 | $5 | Other Models |
Rates from cursor.com/docs/models, verified October 8, 2026. Grok 4.7 output is 2.4× the price of Composer 2.5 output; Claude Opus 5.5 output is 3.3× Grok 4.7. The "10M output tokens" column is output-side only — a labeled unit comparison, not a total-cost estimate, since real agent workloads mix input, cache, and output at very different ratios.
Plan prices themselves are simple: Hobby free, Individual $20/month, Teams $40/user/month (Standard or Premium), Enterprise custom with pooled usage, SCIM, invoice billing, and repo/model/MCP access controls. There is no published Pro+/Ultra price on the live pricing page cards beyond the $20/$40 pair — the higher individual tiers are pitched by usage size in the FAQ rather than a price table, which means the real cost of an agent-heavy individual workflow is discoverable only inside the product.
Hands-On: The Agent CLI
The CLI is the surface platform engineers should actually evaluate first — it is the one that fits existing terminal-driven workflows and CI. We installed it on a clean Linux box with the documented one-liner:
$ curl https://cursor.com/install -fsS | bash
▸ Detected linux/x64
✓ Package downloaded and extracted
✓ Symlink created
✨ Installation Complete!
$ export PATH="$HOME/.local/bin:$PATH"
$ agent --version
2026.10.01-e373342What the installer actually does is worth knowing before you pipe it to a shell: it downloads agent-cli-package.tar.gz from downloads.cursor.com/lab/<version>/<os>/<arch>/, extracts into ~/.local/share/cursor-agent/versions/, and symlinks both agent and cursor-agent into ~/.local/bin. Note the /lab/ path segment — the "CLI" is versioned as a lab package. One more discovery: the old cursor-agent npm package is a dead end, last published January 2025 at 1.0.3 with zero updates since; anything that installs Cursor's CLI from npm in 2026 is installing a two-year-old artifact. The current binary ships only from cursor.com.
Every subcommand requires authentication — agent --list-models, agent -p, even agent status fail cleanly without a login:
$ agent --list-models
Error: Authentication required. Run 'agent login', pass --api-key/--auth-token,
or set CURSOR_API_KEY/CURSOR_AUTH_TOKEN.
$ agent -p "say hi"
Error: Authentication required. Please run 'agent login' first, or set
CURSOR_API_KEY environment variable.
$ agent about
About Cursor CLI
CLI Version 2026.10.01-e373342
Latest 2026.10.01-e373342 (up to date)
Model Auto
Subscription Tier Unknown
OS linux (x64)
Shell bash
User Email Not logged inThe flag surface tells you the operational model of the product. The three approval flags are the ones to read carefully:
--force/--yolo— force-allow commands unless explicitly denied. YOLO is an alias, which tells you exactly how Cursor thinks about its own users.--auto-review— a server-side classifier auto-runs "safe" tool calls and prompts for the rest.--sandbox <enabled|disabled>— explicit sandbox override of the config.
--mode plan gives a read-only planner, --mode ask a read-only Q&A mode, --resume/--continue reattach to sessions, -w/--worktree runs the agent in an isolated git worktree under ~/.cursor/worktrees/, and --output-format json|stream-json makes print mode scriptable. There is also a persist subcommand for sessions that survive terminal disconnects and bedrock for configuring AWS Bedrock usage — a nod to enterprises that refuse direct third-party model egress.
The subcommand that matters most for platform teams is worker:
$ agent worker --help
Run a self-hosted Cloud Agent worker that connects to Cursor and executes
agent tool calls on this machine. Without --pool it is a personal My
Machines worker (no Enterprise plan needed); with --pool it joins a team
Self-Hosted Pool (Enterprise plan + service account API key).
--auth-token-file <path> worker auth token, operator-managed Secret mounts
--worker-dir <path> workspace root exposed to agents (repeatable)
--management-addr <addr> HTTP server: GET /healthz, /readyz (Kubernetes
probes) and /metrics (Prometheus text scrape)
--label key=value worker labels (repeatable)
--idle-release-timeout <seconds> seconds the worker stays connected after
going idle before exit; default 3600; 0 disablesThat is a well-designed worker contract: Kubernetes liveness/readiness probes, a Prometheus scrape endpoint, Secret-mount token files, label-based routing, and a clean idle-exit (exit code 0) designed for a supervisor to restart. For an enterprise that will not let third-party agents touch code outside its network, this — plus the pools feature (named queues, capacity that grows with demand, hibernation for idle machines with reconnect-window restore) — is the strongest argument for Cursor over editor-attached competitors: you can run the entire execution plane in your own infra and let Cursor coordinate.
The iOS remote-control feature shipped October 6 is the same idea pointed at individuals: your local agents keep running on your machine, and the app connects to them — the docs are explicit that the computer must stay on and online, and that the feature is on by default for everyone except Enterprise orgs, where an admin opt-in is required. Read that default again: a phone-app tunnel into the machine running your dev agents is opt-out, not opt-in. For BYOD-heavy orgs without an Enterprise plan, that is a conversation to have with security before rollout, not after.
Guardrails: Read the Fine Print Before You Trust the Agent
Cursor's agent security documentation deserves credit for one thing: it is more honest than most vendor security pages. The key sentences, verbatim from the agent security docs:
- First-party tools that only read or search "don't require approval"; agents "can modify workspace files without approval, except for configuration files" and "changes save immediately to disk."
- Run Modes "range from a simple allowlist to the Auto-review classifier, and they're best-effort guardrails rather than a hard security boundary."
- Network egress is constrained by default: tools "only make network requests to: GitHub, direct link retrieval, web search providers. Agents cannot make arbitrary network requests with default settings."
- Workspace trust — the VS Code-style trust prompt that sandboxes untrusted repos — "is disabled by default," and restricted mode "breaks AI features." The docs' own advice for untrusted repos: "use a basic text editor instead."
- A warning the docs put in bold: with auto-reload enabled, agent changes "might execute before you can review them."
That last cluster is the real risk model for agentic coding: an agent that writes config files immediately to disk, executes code on save via auto-reload, and reaches network endpoints — with guardrails the vendor itself classifies as best-effort. .cursorignore exists for file-level exclusion, MCP connections require per-tool approval, and privacy mode contractually keeps code out of training — those are real controls. But the honest summary is: Cursor's default posture trusts the workspace until you harden it, and the hardening is a collection of speed bumps, not a boundary.
Then there is the 0day. Mindgard disclosed in September 2026 — after reporting it privately since December 15, 2025 — that Cursor on Windows executes a planted git.exe found in the opened repository's root, with no interaction, no prompt, and no warning, repeatedly on a cadence. That is arbitrary code execution from "open a malicious repo." Mindgard's frustration is dated and specific: the issue was still present in the latest tested version after "more than six months and 197+ new versions." Cursor's scale makes the exposure non-trivial — the disclosure cites 7M+ active users and 50K+ companies. The mitigating reality: you need to open an attacker-controlled repo on Windows. The damning reality: a vendor that ships a self-updating binary 197 times in six months left a one-click RCE in the loader path the whole time. If you run Cursor on Windows and open third-party repos, treat this as live and assume the fix when it lands needs verification on your fleet; cloned-repo provenance is now a security input.
Certifications are real and current — SOC 2 Type II, ISO 27001:2022, ISO 42001:2023, AIUC-1, at-least-annual third-party penetration testing, a published subprocessor list on the trust portal, and an explicit no-China-infrastructure statement. The corporate security posture is not the weak point; the client runtime is.
The Cost-Opacity Problem
On July 31, 2026, users noticed the usage page had swapped dollar amounts for token counts, and the CSV export lost its cost columns. The forum thread that followed is a masterclass in quiet metering changes: long-time customers describing the dollar view as the only way they kept tabs on daily spend, with no revert setting and no explanation in the changelog. The HN thread (337 points) had a more pointed subtext — several multi-year paying users said the change tracked with a general post-acquisition pattern of usage opacity, and more than a few said they had already moved their writing to Claude Code or Codex and only kept Cursor for review.
Why this matters more than a normal SaaS dashboard gripe: agent workloads are the highest-variance spend category in the dev-tool budget. A single runaway agent loop can burn through a pool in hours. A dashboard that shows "tokens consumed" against a pool whose dollar conversion depends on which of two pools and which model inside it fired — on a product where the cheap pool is Cursor-owned models — is a dashboard that makes the vendor's cheapest path look free and your overage invisible until the invoice. The admin dashboard on Teams retains usage analytics, and Enterprise gets pooled usage and the AI code tracking API, so the enterprise tier can rebuild the meter externally. Everyone else should plan to export and recompute, because the product no longer does that arithmetic for you.
Critical Failure Modes
- Model supply risk is now demonstrated, not hypothetical. OpenAI models die in Cursor on November 12, 2026. If your team built workflows and prompt habits around GPT-5.x behavior, you are re-validating everything on Grok 4.7/Composer 2.5 or moving to Anthropic's pool at API-rate pricing. Any team that standardizes on Cursor models after this should ask the symmetric question: what happens to Grok economics when the SpaceX relationship or the model roadmap shifts?
- Guardrail drift under YOLO/auto-review.
--yoloand the Auto-review classifier exist because approvals kill agent velocity, and both move you from "human approves each risky call" to "classifier guesses." Cursor labels its own guardrails best-effort; an agent with terminal access, immediate disk writes, and auto-reload can turn a hallucinated install step into an executed one before review. The blast radius is your laptop in local mode — and a whole worker pool in self-hosted mode. - Cost feedback loop removal. Dollar-denominated usage data disappearing from the dashboard and CSV export in the same quarter the model mix shifted toward in-house models is the kind of coincidence FinOps teams are paid to be suspicious of. Without the dollar view, pool overage is only visible at invoice time.
- Open-repo RCE on Windows. The planted-
git.exe0day turns "clone a repo to look at it" into code execution. Combine with agents that auto-run in opened workspaces and the attack surface writes its own chain. - Platform gravity. Origin repos, Projects' shared context, team marketplaces, and bot automations are all retention mechanics. Each is individually reasonable; collectively they mean the cost of leaving Cursor in 2027 is not "export your settings" but "rebuild your delivery automations."
- Remote-control defaults. The phone-to-laptop agent tunnel is default-on for non-Enterprise plans. In an org where laptops hold prod credentials (all of them), a default-on remote-execution path into developer machines deserves an explicit policy decision.
Verdict: Buy for the Execution Plane, Not the Model Story
Cursor in October 2026 is two products wearing one brand. The first is the best-integrated agentic execution platform on the market: editor-to-CLI-to-cloud-to-self-hosted continuity, Kubernetes-grade worker tooling, BYO-sandbox flexibility, and delivery bots that touch the part of the pipeline where money actually leaks (deploy verification, PR security). If you evaluate that product on its own merits — especially the self-hosted worker pools, which let you keep code and secrets inside your network — it is genuinely strong, and no competitor currently matches the span.
The second product is a model-subscription business whose headline asset is a 35-day-old model (Grok 4.7) from a company whose upstream rival just demonstrated the ability to cut off a model line by decree, whose usage pricing nudges users toward in-house models via pool asymmetry, and whose cost transparency regressed this quarter. The Nov 12 shutoff is not a reason to avoid Cursor — Anthropic and Google models remain, and Grok 4.7's published rates are competitive ($2/$6 against Sonnet 5.5's $2/$10, with a 4× cache-read discount). It is a reason to treat every model subscription inside an agent platform as replaceable, and to keep your prompts, rules, and evals portable enough to survive a forced model migration.
Who Should Skip This
- Teams standardized on OpenAI models for agent work. You have 35 days to migrate or re-plan. Do not adopt Cursor now and discover your eval suite in November.
- Windows-first shops that open third-party repos. The planted-
git.exeRCE was unfixed for the entire review window. Security-review tooling inside an IDE does not compensate for an unfixed RCE in the IDE itself. - Orgs that need hard execution boundaries. Cursor's own docs say the guardrails are best-effort, not a security boundary. If your compliance posture requires provable confinement, the sandbox story — client-side, config-dependent, overridable by flag — is not it; use dedicated execution environments (ephemeral VMs, containers with policy) and keep the agent inside them.
- Cost-sensitive individual and small-team users who need dollar metering. The usage dashboard now optimizes for the vendor, not the spender. If nobody on your team is going to build an external meter from the token export, budget surprises are a feature now.
- Enterprises that cannot accept a default-on remote-control path to developer machines (unless on the Enterprise plan, where it is admin-gated).
- Anyone buying "the editor" expecting an editor. The value is the platform; if you only want chat-assisted editing, the free VS Code extensions your cloud vendor ships will cover you without the platform gravity.
References & Further Reading
- Cursor pricing page — plans and included features, verified October 8, 2026.
- Cursor models & pricing docs — per-model token rates and the two usage pools.
- Grok 4.7 announcement and model card — in-house frontier model, SpaceX training partnership, CursorBench 4.0 score.
- Cursor changelog — Remote control (Oct 6, 2026), Rollouts and Security Review (Sep 23), Projects (Sep 10), self-hosted machines (Sep 2).
- Cursor CLI overview — install, modes, print mode for CI.
- Cursor agent security defaults — approval model, network egress allowlist, workspace trust status, best-effort guardrail disclaimer.
- Cursor security page — SOC 2 Type II, ISO 27001/42001, AIUC-1, subprocessor and infrastructure posture.
- OpenAI's decision on Cursor — the November 12, 2026 shutoff notice and its reasoning.
- Mindgard's Cursor 0day disclosure — planted
git.exeexecution, reported December 15, 2025, still present September 2026. - Cursor forum: usage page dollars-to-tokens change — July 31, 2026 thread with staff and user responses.
- Hacker News discussion of OpenAI's decision — 852 points; useful cross-section of buyer sentiment post-acquisition.
- cursor-agent on npm — the stale January 2025 package that should not be confused with the current CLI.