Case Study: Cursor strengthens SaaS security with Reco

A Reco Case Study

Preview of the Cursor Case Study

Cursor secures 1TB EC2 background agents with Reco

The security research team at Reco investigated a potential vulnerability within the agent infrastructure of Cursor, a self-hosted SaaS application. The challenge was to determine if Cursor's Background Agent, which performs critical operations with deep infrastructure access, could be compromised to gain control over its underlying cloud environment.

Reco successfully demonstrated a full attack chain, exploiting a terminal feature to gain remote command execution, escalate privileges to root within a Docker container, and ultimately escape to the host EC2 instance via SSH key injection. This proved that even a well-configured desktop SaaS agent could present a significant third-party risk. As a result of this research, Reco supports integration with Cursor to provide customers with complete visibility and proactive protection as part of a comprehensive SaaS security strategy.


View this case study…

Reco

21 Case Studies