Head to head
Aider vs Cursor
Comparing 4 documented Aider incidents against 4 for Cursor.
Verdict
Aider has the lower average failure severity (4.5/10 vs 8.2/10), making it the statistically safer choice of the two — though both agents have documented critical incidents.
| Metric | Aider | Cursor |
|---|---|---|
| Documented incidents | 4 | 4 |
| Average severity | 4.5 | 8.2 |
| Critical | 0 | 3 |
| High | 0 | 0 |
| Verified | 1 | 4 |
Severity at a glance
Failure modes
The incidents behind these numbers
Aider
4.8Aider exits with code 0 after a fatal API connection failure, masking hard failures as successful headless runs4.6Aider silently discards a model's correct diff response as "no tracked changes" when it guesses the wrong edit format4.4Aider's headless `--message` mode silently swallows slash commands (`/model`, `/ask`, `/architect`) and exits 0 having done nothing4.2Aider's unified-diff coder silently drops the partial-application warning when one hunk succeeds and another fails
Cursor
10.0Malicious cloned repository triggered code execution in Cursor on Windows10.0Cursor AI agent deleted PocketOS's entire production database and backups in 9 seconds9.8Cursor's terminal sandbox trusted an agent-set working directory, letting zero-click prompt injection escape it and gain code execution (CVE-2026-50548)2.9Cursor's own support AI 'Sam' invented a one-device login policy, triggering subscription cancellations