
Your trust issues were right 🫣 CVE-2025-54136 affects Cursor versions 1.2.4 and below and can lead to remote code execution due to how MCP configurations are handled. The first time an MCP config is introduced, the user approves it. After that, any changes to the same file are automatically trusted. In shared environments or collaborative projects, this opens the door to stealthy payload swaps and potential lateral movement starting from a developer workstation. Swipe through the slides to break down the exploit path and mitigation steps, and save this post to review your MCP configs later. Train humans and agents side by side to face the next wave of advanced threats: https://okt.to/xarz7V #CyberSecurity #CVE #AppSec #DevSecOps #ThreatResearch #Infosec #HackTheBox
Post summary
CVE-2025-54136 in Cursor 1.2.4 and earlier allows remote code execution by exploiting MCP config handling, enabling stealth payload swaps and potential lateral movement; the post outlines the exploit path and mitigation steps.








