
Exfiltration of secrets, RCE via a simple file read by the agent. It happened to Cursor (CVE-2025-59944), to Devin, and the number of injection payloads on the web jumped by 32% in 3 months. Your agent reads PDFs, README, web pages every day. It does not distinguish between data and instructions. We built cerbere-ag (http://www.cerbereag.site) for this: each prompt and each tool call is inspected and logged in real time, connected in one line.
Post summary
The post discloses a newly identified CVE‑2025‑59944 impacting Cursor and Devin, detailing an RCE and secret exfiltration through a simple file read and noting a 32% rise in web injection payloads over three months.


