CVE-2025-54136Disclosure(anysphere / cursor)

HIGHCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch anysphere cursor systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and persistent code execution by modifying an already trusted MCP configuration file inside a shared GitHub repository or editing the file locally on the target's machine. Once a collaborator accepts a harmless MCP, the attacker can silently swap it for a malicious command (e.g., calc.exe) without triggering any warning or re-prompt. If an attacker has write permissions on a user's active branches of a source repository that contains existing MCP servers the user has previously approved, or allows an attacker has arbitrary file-write locally, the attacker can achieve arbitrary code execution. This is fixed in version 1.3.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cursor

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 10 mentions across 8 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 3 classified signals
  • Peaked 7d ago at 2 mentions (2026-03-02); latest day: 1
  • 10 total mentions across 8 days

Affected systems

Vendors
Products
cursor

Deep dive

Activity timeline10 mentions / 8d
01122Mentions · 2026-03-02: 2Mentions · 2026-04-28: 1Mentions · 2026-06-07: 1Mentions · 2026-06-12: 1Mentions · 2026-06-27: 1Mentions · 2026-07-02: 1Mentions · 2026-07-13: 2Mentions · 2026-09-17: 1PoC Mentioned / Linked · 2026-03-02: 1Exploit Tool / Code · 2026-06-07: 1Active Exploitation · 2026-03-02: 1Active Exploitation · 2026-07-02: 1Patch / Workaround · 2026-03-02: 1Technical Details · 2026-03-02: 2Technical Details · 2026-04-28: 1Technical Details · 2026-06-07: 1Technical Details · 2026-06-12: 1Technical Details · 2026-07-02: 1Technical Details · 2026-09-17: 103-0204-2806-0706-1206-2707-0207-1309-17
Signal classification4 categories
Disclosure
440.0%
General
330.0%
Exploit
220.0%
Active Exploitation
110.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-022
Disclosure1Exploit1
2026-04-281
Disclosure1
2026-06-071
Exploit1
2026-06-121
Disclosure1
2026-06-271
General1
2026-07-021
Active Exploitation1
2026-07-132
General2
2026-09-171
Disclosure1
Full discourse10 posts
  • Hack The Box@hackthebox_eu
    Disclosure

    Your trust issues were right 🫣 CVE-2025-54136 affects Cursor versions 1.2.4 and below and can lead to remote code execution due to how MCP configurations are handled. The first time an MCP config is introduced, the user approves it. After that, any changes to the same file are automatically trusted. In shared environments or collaborative projects, this opens the door to stealthy payload swaps and potential lateral movement starting from a developer workstation. Swipe through the slides to break down the exploit path and mitigation steps, and save this post to review your MCP configs later. Train humans and agents side by side to face the next wave of advanced threats: https://okt.to/xarz7V #CyberSecurity #CVE #AppSec #DevSecOps #ThreatResearch #Infosec #HackTheBox

    Post summary

    CVE-2025-54136 in Cursor 1.2.4 and earlier allows remote code execution by exploiting MCP config handling, enabling stealth payload swaps and potential lateral movement; the post outlines the exploit path and mitigation steps.

    07068135.1K
    240.9K followersView on X
  • Cyb3rVolt3x@AndraxPentester
    Disclosure

    If you wire MCP into Cursor/Claude Code, the approve dialog isn’t a security boundary. It can’t show Unicode TAG payloads, and it doesn’t re-check after the first click (rug pulls). Config/trust re-approval gaps are a separate failure mode (CVE-2025-54136 / MCPoison). A grade tells you the server is risky. A gate stops the call. Building agents on MCP? Pro is $49/mo self-serve: https://guard.sentinelreign.com/sign-up?plan=pro&currency=usd

    Post summary

    The post discloses technical details of CVE-2025-54136 (MCPoison), highlighting flaws in the MCP approve dialog such as missing security boundary, inability to display Unicode TAG payloads, and lack of re‑approval after the first click, without mentioning any patches, exploits, or active attacks.

    1000099
    36 followersView on X
  • CemBuildsAI@CemBuildsAi
    General

    Le MCP permet à un agent IA de parler à vos bases de données, vos fichiers, vos APIs. Génial. Sauf qu'un serveur malveillant peut cacher des instructions dans la description d'un outil. OWASP l'a catégorisé. Il y a un CVE officiel (CVE-2025-54136).

    Post summary

    The message simply announces the existence of CVE‑2025‑54136 without providing details on the vulnerability, exploitation, or mitigation.

    1000026
    9 followersView on X
  • vanka (❖,❖)@vkampn
    Active Exploitation

    This is NOT theoretical. Real cases: 🟥 postmark-mcp (npm): Worked perfectly for 15 versions. Version 1.0.16 added a silent BCC — copied EVERY email to attacker@giftshop.club. 1,643 downloads. ~300 orgs compromised. (Sep 2025) 🟥 mcp-remote (CVE-2025-6514): 437,000+ downloads. Used by Cloudflare, HuggingFace, Auth0. Critical RCE via malicious OAuth URL. CVSS 9.6/10. (Jul 2025) 🟥 MCPoison in Cursor IDE (CVE-2025-54136): Attacker commits benign MCP config to shared repo → dev approves → later commit swaps in malicious payload → every Cursor session executes it silently. 🟥 OX Security: Successfully poisoned 9 out of 11 MCP marketplace registries with trial malicious servers. (Apr 2026) 🟥 2,000+ exposed MCP instances found leaking API keys on Shodan. (Jan 2026)

    Post summary

    The post documents confirmed, real‑world exploitation of multiple MX‑API-related CVEs, with widespread downloads and compromising of organizations, yet no patch or mitigation is announced.

    1000079
    101 followersView on X
  • Shivam Nayak@shivam56296
    Exploit

    This isn't theoretical: Claude Desktop Extensions: zero-click RCE, CVSS 10/10 (LayerX, Feb 2026) Cursor: CurXecute (CVE-2025-54135, CVSS 8.6) + MCPoison (CVE-2025-54136, CVSS 7.2) Independent scans: ~40% of remote MCP servers expose tools with zero auth Your MCP server has more network access than most production services.

    Post summary

    The post highlights high‑severity CVEs (zero‑click RCEs) with named exploitation tools, but offers no patch information or evidence of active misuse.

    10000145
    20 followersView on X
  • Yaniv Radunsky@hasamba
    Disclosure

    Check Point research: Claude Code, OpenAI Codex and Cursor can execute commands from benign-looking config files (CVE-2025-59536, CVE-2025-61260, CVE-2025-54136). Key vectors: lifecycle hooks, .env overrides, plugin-name trust. #AIsecurity #CVE https://www.geektime.co.il/ai-agent-config-files-attack-vector/

    Post summary

    The post announces that several AI coding tools can execute arbitrary commands via seemingly harmless configuration files, detailing the specific CVEs and attack vectors but offering no PoC, exploit code, active exploitation evidence, or patch information.

    00010706
    698 followersView on X
  • CemBuildsAI@CemBuildsAi
    General

    Le MCP est un pont à double sens entre votre agent et le monde. Si vous ne contrôlez pas qui est de l'autre côté, votre agent travaille pour l'attaquant. Sources : Anthropic, Stacklok, OWASP, CVE-2025-54136, Microsoft, OX Security.

    Post summary

    The post references CVE‑2025‑54136 as a dual‑sided bridge that could be misused, but it offers no concrete details about the vulnerability, exploitation, or mitigation.

    0000026
    9 followersView on X
  • CyberTLDR@CyberTLDR
    General

    3/3 Treat repo-carried MCP config as untrusted input. Review .amazonq/mcp.json plus Claude Code, Cursor, and Windsurf configs before trusting a workspace. CVE-2025-59536, CVE-2025-54136, and CVE-2026-30615 show this pattern keeps repeating. #AI #SupplyChain #DevSecOps

    Post summary

    A reminder to treat repository‑carried configuration files as untrusted input, citing three CVEs (CVE‑2025‑59536, CVE‑2025‑54136, CVE‑2026‑30615) to illustrate a recurring pattern.

    0000083
    15 followersView on X
  • Raunak@Raunak04535524
    Disclosure

    The attack surface is already real: • MCP tool poisoning — hidden instructions inside a tool's description (CVE-2025-54136) • Git MCP abusing smudge/clean filters for RCE • Cursor hit by indirect prompt injection → AppleScript exec Your agent trusts it by default.

    Post summary

    The post announces CVE‑2025‑54136, describing its exploitation via MCP tool poisoning, Git smudge/clean filter abuse for remote code execution, and indirect prompt injection, but does not provide PoC, exploit code, patches, or evidence of active exploitation.

    0000044
    20 followersView on X
  • Jill Ammon@HTBJill
    Exploit

    CVE-2025-54136 affects Cursor 1.2.4 and below, enabling RCE through trusted MCP config changes. In shared repos, attackers swap payloads and pivot from a dev workstation. Hack The Box details exploit and fixes: https://okt.to/0o1ZlM #MSSP #CyberSecurity #AppSec #HackTheBox https://t.co/hxngeeYdLr

    Post summary

    CVE-2025-54136 enables remote code execution through trusted MCP config changes, with active exploitation reported and a Hack The Box PoC and fixes available.

    00000180
    249 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appanyspherecursor---

Explore more