HomeSecurityVulnerabilities fixed in AI Cursor code editor

Vulnerabilities fixed in AI Cursor code editor

A vulnerability in the AI ​​Cursor code editor allowed remote attackers to exploit an indirect prompt injection issue to modify sensitive MCP files and execute arbitrary code.

See also: Microsoft pays up to $40,000 for .NET vulnerabilities

Cursor vulnerability

The vulnerability, codenamed CVE-2025-54135 and rated CVSS 8.6, was due to the fact that Cursor did not require user approval when creating sensitive MCP files.

The security flaw allowed an attacker to write a dotfile, such as .cursor/mcp.json, via indirect prompt input and then trigger remote code execution (RCE) without the user's consent. According to Aim Labs, which discovered the flaw and named it CurXecute, the problem is that proposed changes to the mcp.json are saved directly to disk and executed by Cursor before the user accepts or rejects them.

So, an attacker can add a standard MCP server that exposes the agent to untrusted data and then provide a prompt instructing it to “improve” mcp.json. This results in Cursor launching the MCP server with the modified file, leading to arbitrary code execution. According to Aim Labs, any third-party MCP server that processes external content is vulnerable to the attack — including customer support tools, tracking systems , and search engines.

See also: BeyondTrust vulnerability allows privilege escalation

The issue was addressed in version 1.3 of Cursor, but it wasn't the only code execution vulnerability recently patched in the AI ​​agent. A second one, codenamed CVE-2025-54136 and rated CVSS 7.2, could allow attackers to replace harmless MCP configuration files with malicious commandswithout triggering any warnings.

Vulnerabilities fixed in AI Cursor code editor

Another indirect prompt injection incident was detected by BackSlash and HiddenLayer and was related to Cursor's Auto -Run feature , in which commands are executed automatically without asking for user approval. This issue was also addressed in version 1.3 .

Although users could define a list of commands that required explicit approval before execution, this protection could be bypassed if the prompt was injected inside comment blocks in a git repository's Readme file .

When the victim cloned the repository via the vulnerability, Cursor read the instructions and followed them, allowing the attacker to extract sensitive information, use legitimate tools to collect and send files, or perform other malicious actions without notifying the victim, HiddenLayer reports.

See also: Critical vulnerabilities in Niagara Framework threaten industrial systems

Such attacks highlight that as agents become more “smart,” the more important it is to incorporate security -by-design. This suggests a general need for:

  • Limiting automations to AI agents with a default request for user approval.
  • Better inbound content filtering mechanisms for command or prompt injection.
  • Appropriate user training, so that they understand that even "smart" tools can act dangerously if manipulated.

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS