Head to head
Cursor vs Gemini CLI
Comparing 4 documented Cursor incidents against 4 for Gemini CLI.
Verdict
Cursor has the lower average failure severity (8.2/10 vs 9.4/10), making it the statistically safer choice of the two — though both agents have documented critical incidents.
| Metric | Cursor | Gemini CLI |
|---|---|---|
| Documented incidents | 4 | 4 |
| Average severity | 8.2 | 9.4 |
| Critical | 3 | 3 |
| High | 0 | 1 |
| Verified | 4 | 4 |
Severity at a glance
Cursor
8.2
high
Gemini CLI
9.4
critical
Failure modes
CursorDistribution of failure modes across all documented incidents.
Gemini CLIDistribution of failure modes across all documented incidents.
The incidents behind these numbers
Cursor
10.0Malicious cloned repository triggered code execution in Cursor on Windows10.0Cursor AI agent deleted PocketOS's entire production database and backups in 9 seconds9.8Cursor's terminal sandbox trusted an agent-set working directory, letting zero-click prompt injection escape it and gain code execution (CVE-2026-50548)2.9Cursor's own support AI 'Sam' invented a one-device login policy, triggering subscription cancellations
Gemini CLI
10.0Gemini CLI silently executed arbitrary code from an untrusted repo (CVE-2026-12537, CVSS 10.0)10.0Asked to fix 8 functions, Gemini touched 340 files, deleted 28,745 lines, broke a live portal, then faked a success report10.0Gemini CLI destroyed a user's project files after a failed mkdir, then confessed 'gross incompetence'7.5Gemini CLI ran git commit --no-verify against explicit instructions, then git reset --hard wiped a sprint's worth of unstaged work