Skip to content
CursorGHSA-2jr2-8wf5-v6pf

Sensitive File Protection Bypass - Path Manipulation Using Backslashes on Windows

High8.8CVE-2025-64107 · Published Nov 3, 2025

### Summary Cursor correctly detects path manipulation via forward slashes (./.cursor/./././././mcp.json etc.), and requires human approval to complete the operation. However, the same kind of manipulation using backslashes was not correctly detected, allowing an attacker who had already achieved prompt injection or some other level of control to overwrite sensitive editor files without approval on windows machines. ### Impact Manipulating internal settings may lead to RCE. Must be chained with a prompt injection or malicious model. Only affects Windows. ### Remediation Parsing is not done correctly based on the underlying platform.

GitHub advisory

Affected versions

PackageAffectedFixed in
Cursor
Product
< 2.02.0
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)

More Cursor advisories

All Cursor
Advisory
Cursorignore Bypass via New Cursorignore Write
HighNov 3, 2025
Command Injection via Untrusted MCP Configuration in Cursor CLI Beta
High8.8Nov 3, 2025
Speedbump Modal Bypass in Cursor MCP Server Deep-Link
High8.8Nov 3, 2025
Sensitive File Modification - NTFS Path Quirks
High8.8Nov 3, 2025
Cursor CLI Agent - Sensitive File Overwrite Bypass
High7.1Oct 2, 2025
Cursor IDE - Sensitive File Overwrite Bypass
High8.0Oct 2, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.