Why Cursor Writes IDOR Into Your API Routes (CWE-639)
A developer discovered that Cursor, an AI code editor, generated an API endpoint vulnerable to Insecure Direct Object Reference (IDOR, CWE-639). The endpoint authenticated the user but failed to verif…