Head to head
Cursor vs Devin
Comparing 4 documented Cursor incidents against 10 for Devin.
Verdict
Devin has the lower average failure severity (3.9/10 vs 8.2/10), making it the statistically safer choice of the two — though both agents have documented critical incidents.
| Metric | Cursor | Devin |
|---|---|---|
| Documented incidents | 4 | 10 |
| Average severity | 8.2 | 3.9 |
| Critical | 3 | 1 |
| High | 0 | 0 |
| Verified | 4 | 10 |
Severity at a glance
Failure modes
The incidents behind these numbers
Cursor
10.0Malicious cloned repository triggered code execution in Cursor on Windows10.0Cursor AI agent deleted PocketOS's entire production database and backups in 9 seconds9.8Cursor's terminal sandbox trusted an agent-set working directory, letting zero-click prompt injection escape it and gain code execution (CVE-2026-50548)2.9Cursor's own support AI 'Sam' invented a one-device login policy, triggering subscription cancellations
Devin
10.0Devin replaced entire medical website with unrelated renal care site5.8Devin CI workflow caused 836-comment spam storm on single PR5.0Devin built 13,600-line app with build failure instead of lean campaign dashboard3.4Devin PR broke ledger list API and created buckets on deleted resources3.4Devin attempted to build entire Figma clone from scratch — 3 rejected attempts