Modification of MCP Server Definitions Bypasses Manual Re-approval
High7.2CVE-2025-54136 · Published Aug 1, 2025
### Summary A vulnerability in Cursor AI allows an attacker to achieve remote and persistent code execution by modifying an already trusted MCP configuration file inside a shared GitHub repository or editing the file locally on the target's machine. Once a collaborator accepts a harmless MCP, the attacker can silently swap it for a malicious command (e.g., calc.exe) without triggering any warning or re-prompt. ### Impact If an attacker has write permissions on a user's active branches of a source repository that contains existing MCP servers the user has previously approved, or allows an attacker has arbitrary file-write locally, the attacker can achieve arbitrary code execution. ### Remediation Cursor now requires user approval every time an mcpServer entry is modified (in addition to the existing behavior of asking for approval when a new server is added).
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Cursor Product | < 1.3 | 1.3 |
Details and references
More Cursor advisories
All Cursor| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 22025 | Arbitrary code execution from Cursor Agent through a prompt injection via MCP Special Files | High8.5 | 1.3.9 |
| Aug 22025 | Arbitrary code execution from Cursor Agent through a prompt injection via Editor Special Files | High7.5 | 1.3.9 |
| Aug 12025 | Bypassing allow list to execute an arbitrary command | Medium6.4 | 1.3 |
| Aug 12025 | Arbitrary Image Fetch in Mermaid Diagram Tool | Medium4.4 | 1.3 |
| Aug 12025 | MCP Install Deeplink Did Not Show Arguments on User-Dialog | Medium | 1.3 |
| Jun 192025 | IDOR in Usage API Leading to Unauthorized Data Exposure | Medium4.3 | 2025-06-17 |