CVE-2025-54135Disclosure(anysphere / cursor)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions below 1.3.9, If the file is a dotfile, editing it requires approval but creating a new one doesn't. Hence, if sensitive MCP files, such as the .cursor/mcp.json file don't already exist in the workspace, an attacker can chain a indirect prompt injection vulnerability to hijack the context to write to the settings file and trigger RCE on the victim without user approval. This is fixed in version 1.3.9.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-829

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cursor

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-05-20); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
cursor

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-20: 1Mentions · 2026-06-07: 1Mentions · 2026-09-23: 1Technical Details · 2026-05-20: 1Technical Details · 2026-06-07: 1Technical Details · 2026-09-23: 105-2006-0709-23
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Classification over time
DateTotalLabels
2026-05-201
Disclosure1
2026-06-071
General1
2026-09-231
Disclosure1
Full discourse3 posts
  • Secure the AI 🤖@sixi4ai
    Disclosure

    1. CVE-2025-54135 (Cursor IDE): Silent file-write flaw allowed an indirect prompt injection to craft a malicious `.cursor/mcp.json`. Cursor's Auto-Run executed arbitrary host commands without confirmation.

    Post summary

    The text discloses CVE-2025-54135 in Cursor IDE, describing a silent file-write flaw enabling indirect prompt injection that leads to arbitrary command execution. It provides technical detail but mentions no PoC, exploit tool, active exploitation, or patch.

    1000050
    165 followersView on X
  • Shivam Nayak@shivam56296
    General

    This isn't theoretical: Claude Desktop Extensions: zero-click RCE, CVSS 10/10 (LayerX, Feb 2026) Cursor: CurXecute (CVE-2025-54135, CVSS 8.6) + MCPoison (CVE-2025-54136, CVSS 7.2) Independent scans: ~40% of remote MCP servers expose tools with zero auth Your MCP server has more network access than most production services.

    Post summary

    Highlights zero‑click RCE vulnerabilities (Claude Desktop Extensions, CVE‑2025‑54135/36) with identified CVSS scores, but lacks PoC, exploit code, patches or evidence of wild exploitation.

    10000145
    20 followersView on X
  • Andrew Dev@just_andydev
    Disclosure

    7/ Prompt Injection Attacks Attackers hide malicious instructions in files the AI reads as trusted context. Success rates up to 84% against Cursor and GitHub Copilot. 8/ Vulnerable AI Tools Themselves CVE-2025-54135 let attackers execute arbitrary commands on a developer's machine through an active MCP server connected to Cursor. No user interaction required.

    Post summary

    The note discloses CVE‑2025‑54135, detailing how attackers can execute arbitrary commands on a developer’s machine through an active MCP server connected to Cursor, while providing no PoC, exploit code, or evidence of active exploitation.

    10000990
    2.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appanyspherecursor---

Explore more