CVE-2025-59944Active Exploitation(anysphere / cursor)

LOWCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for anysphere cursor systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Cursor is a code editor built for programming with AI. Versions 1.6.23 and below contain case-sensitive checks in the way Cursor IDE protects its sensitive files (e.g., */.cursor/mcp.json), which allows attackers to modify the content of these files through prompt injection and achieve remote code execution. A prompt injection can lead to full RCE through modifying sensitive files on case-insensitive fileystems. This issue is fixed in version 1.7.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-178

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cursor

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-26); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
cursor

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-26: 1Mentions · 2026-06-09: 1Mentions · 2026-09-23: 1Active Exploitation · 2026-04-26: 1Technical Details · 2026-04-26: 1Technical Details · 2026-09-23: 104-2606-0909-23
Signal classification3 categories
Active Exploitation
133.3%
General
133.3%
Disclosure
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-261
Active Exploitation1
2026-06-091
General1
2026-09-231
Disclosure1
Full discourse3 posts
  • Christopher Dikesa@dikesa_dev
    Disclosure

    Exfiltration of secrets, RCE via a simple file read by the agent. It happened to Cursor (CVE-2025-59944), to Devin, and the number of injection payloads on the web jumped by 32% in 3 months. Your agent reads PDFs, README, web pages every day. It does not distinguish between data and instructions. We built cerbere-ag (http://www.cerbereag.site) for this: each prompt and each tool call is inspected and logged in real time, connected in one line.

    Post summary

    The post discloses a newly identified CVE‑2025‑59944 impacting Cursor and Devin, detailing an RCE and secret exfiltration through a simple file read and noting a 32% rise in web injection payloads over three months.

    20180126
    85 followersView on X
  • Kage Martin@kagemartx
    General

    CVE-2025-59944 should have scared more people than it did. been thinking about it for weeks.

    Post summary

    The post remarks on CVE-2025-59944 but provides no additional technical, exploitation, or mitigation information.

    1001035
    154 followersView on X
  • Prismor@prismor_dev
    Active Exploitation

    A malicious Google Doc triggered an AI coding agent to fetch attacker instructions from an MCP server, run a Python payload, and harvest secrets, automatically. CVE-2025-59944 did the same via a one-char typo in a config file path.

    Post summary

    The post highlights that CVE-2025-59944 is actively exploited in the wild, with malicious Google Docs leveraging a typo in a configuration path to run payloads and harvest secrets. No PoC link or patch is cited, but a clear technical bug is identified.

    10010712
    356 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appanyspherecursor---

Explore more