
1. CVE-2025-54135 (Cursor IDE): Silent file-write flaw allowed an indirect prompt injection to craft a malicious `.cursor/mcp.json`. Cursor's Auto-Run executed arbitrary host commands without confirmation.
Post summary
The text discloses CVE-2025-54135 in Cursor IDE, describing a silent file-write flaw enabling indirect prompt injection that leads to arbitrary command execution. It provides technical detail but mentions no PoC, exploit tool, active exploitation, or patch.


