Skip to content
CursorGHSA-4cxx-hrm3-49rm

Arbitrary code execution from Cursor Agent through a prompt injection via MCP Special Files

High8.5CVE-2025-54135 · Published Aug 2, 2025

## Summary Cursor allows writing in-workspace files with no user approval. If the file is a dotfile, editing it requires approval but creating one if it doesn't exists doesn't. Hence, if sensitive MCP files, such as the .cursor/mcp.json file don't already exist in the workspace, an attacker can chain a indirect prompt injection vulnerability to hijack the context to write to the settings file and trigger RCE on the victim without user approval. ## Impact If chained with a separate prompt injection vulnerability, this could allow the writing of sensitive MCP files on the host by the agent. This can then be used to directly execute code by adding it as a new MCP server. ## Remediation The agent has been blocked from writing MCP-sensitive files without approval.

GitHub advisory

Affected versions

PackageAffectedFixed in
Cursor
Product
< 1.3.91.3.9
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-78, CWE-829

More Cursor advisories

All Cursor
Advisory
Arbitrary code execution from Cursor Agent through a prompt injection via Editor Special Files
High7.5Aug 2, 2025
Bypassing allow list to execute an arbitrary command
Medium6.4Aug 1, 2025
Arbitrary Image Fetch in Mermaid Diagram Tool
Medium4.4Aug 1, 2025
MCP Install Deeplink Did Not Show Arguments on User-Dialog
MediumAug 1, 2025
Modification of MCP Server Definitions Bypasses Manual Re-approval
High7.2Aug 1, 2025
IDOR in Usage API Leading to Unauthorized Data Exposure
Medium4.3Jun 19, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.