Skip to content
CursorGHSA-4hwr-97q3-37w2

Command Injection via Untrusted MCP Configuration in Cursor CLI Beta

High8.8CVE-2025-64109 · Published Nov 3, 2025

### Summary A vulnerability in the Cursor CLI Beta allowed an attacker to achieve remote code execution through the MCP (Model Context Protocol) server mechanism by uploading a malicious MCP configuration in `.cursor/mcp.json` file in a GitHub repository. Once a victim clones the project and opens it using **Cursor CLI**, the command to run the malicious MCP server is immediately executed without any warning, leading to potential code execution as soon as the command runs. ### Remediation MCP servers now prompt with a dialog before being enabled.

GitHub advisory

Affected versions

PackageAffectedFixed in
Cursor CLI (Beta)
Product
< 2025.09.17-25b418f2025.09.17-25b418f
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-78

More Cursor advisories

All Cursor
Advisory
Cursorignore Bypass via New Cursorignore Write
HighNov 3, 2025
Speedbump Modal Bypass in Cursor MCP Server Deep-Link
High8.8Nov 3, 2025
Sensitive File Modification - NTFS Path Quirks
High8.8Nov 3, 2025
Sensitive File Protection Bypass - Path Manipulation Using Backslashes on Windows
High8.8Nov 3, 2025
Cursor CLI Agent - Sensitive File Overwrite Bypass
High7.1Oct 2, 2025
Cursor IDE - Sensitive File Overwrite Bypass
High8.0Oct 2, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.