Skip to content
CursorGHSA-43wj-mwcc-x93p

Arbitrary Image Fetch in Mermaid Diagram Tool

Medium4.4CVE-2025-54132 · Published Aug 1, 2025

### Summary Cursor supports a tool called Mermaid to render diagrams. While testing it was observed that mermaid allows embedding images which then get rendered by Cursor in the chat box. An attacker can use this to exfiltrate sensitive information to a third-party attacker controlled server through an image fetch after successfully performing a prompt injection. A malicious model (or hallucination/backdoor) might also trigger this exploit at will. ### Impact This issue requires prompt injection from malicious data (web, image upload, source code) in order to exploit. In that case, it can send sensitive information to an attacker-controlled external server. ### Remediation All remote images are removed from the mermaid diagram before rendering.

GitHub advisory

Affected versions

PackageAffectedFixed in
Cursor
Product
< 1.31.3
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)

More Cursor advisories

All Cursor

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.