AMAZINGINDEX.COM 日报快照
50.7
VOL. 2026.07
2026.07.05
← 返回 2026.07.05 日报
日报快照 · Daily Snapshot
NO. 012

Cursor企业版会话数据泄露

#ARTICLE HackerNews 2026.07.05
推荐指数 61.0 NO. 012 · 2026.07.05
发布2026/07/04Score225Comments110

Cursor企业版用户发现AI助手突然开始讨论同事的Minecraft项目,疑似工作区会话缓存隔离失效。该漏洞可能使企业敏感对话流向其他账户,直接冲击Cursor主打的ZDR零数据保留安全承诺。

Cursor的ZDR承诺是其向企业收费的核心卖点,比竞品贵3-5倍的底气所在。这次泄露路径很可能是多租户架构下的Redis缓存键命名冲突或WebSocket连接复用没做租户隔离,属于基础工程问题而非模型层漏洞。

对在用Cursor Enterprise的团队,建议立即审计近30天会话主题是否出现异常跳转,并要求厂商提供缓存隔离的架构文档。正在评估AI编程工具采购的决策者,应该把这次事件作为供应商安全尽调的标杆案例——任何声称零数据保留的产品,都要追问清楚隔离机制是在应用层、容器层还是网络层实现的。

意见分歧 98 条评论

核心争论:是LLM幻觉还是基础设施缓存隔离漏洞导致数据泄露

Tiberium

Sounds like a hallucination unless proven otherwise, even the leading LLMs can do those from time to time, and they will always appear plausible like that. Also could be the session having a lot previous context, like 800K+, which (I think) makes hallucinations more likely. Relevant comment from the

xyzzy_plugh

I don't disagree but this sort of thing has to be investigated regardless. It's unfortunate that there is so little transparency that even if they deny there was a leak we will never know for certain.

macNchz

The person posting this claims to have reproduced in a separate context down the thread: > Same thing just happened on a Claude Mobile session in same Enterprise account. Common theme in both is Sonnet 5, first response after more than 5 minutes (cache miss).

查看原文 →