CursorGHSA-4hwr-97q3-37w2
Command Injection via Untrusted MCP Configuration in Cursor CLI Beta
High8.8CVE-2025-64109 · Published Nov 3, 2025
### Summary A vulnerability in the Cursor CLI Beta allowed an attacker to achieve remote code execution through the MCP (Model Context Protocol) server mechanism by uploading a malicious MCP configuration in `.cursor/mcp.json` file in a GitHub repository. Once a victim clones the project and opens it using **Cursor CLI**, the command to run the malicious MCP server is immediately executed without any warning, leading to potential code execution as soon as the command runs. ### Remediation MCP servers now prompt with a dialog before being enabled.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Cursor CLI (Beta) Product | < 2025.09.17-25b418f | 2025.09.17-25b418f |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-78
More Cursor advisories
All Cursor| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Nov 32025 | Cursorignore Bypass via New Cursorignore Write | High | 2.0 |
| Nov 32025 | Speedbump Modal Bypass in Cursor MCP Server Deep-Link | High8.8 | 2.0 |
| Nov 32025 | Sensitive File Modification - NTFS Path Quirks | High8.8 | 2.0 |
| Nov 32025 | Sensitive File Protection Bypass - Path Manipulation Using Backslashes on Windows | High8.8 | 2.0 |
| Oct 22025 | Cursor CLI Agent - Sensitive File Overwrite Bypass | High7.1 | 2025.09.17-25b418f |
| Oct 22025 | Cursor IDE - Sensitive File Overwrite Bypass | High8.0 | 1.7 |