Skip to content
CursorGHSA-534m-3w6r-8pqr

Bypassing allow list to execute an arbitrary command

Medium6.4CVE-2025-54131 · Published Aug 1, 2025

### Summary An attacker can bypass allow list in auto-run mode with backtick(\`) character or `$(cmd)`. ### Impact If a user has swapped Cursor from it's default settings (requiring approval for every terminal call) to an allowlist, an attacker can execute arbitrary command execution outside of the allowlist without user approval. An attacker can trigger this vulnerability if chained with indirect prompt injection. ### Remediation The allowlist logic has switched to a more robust parser.

GitHub advisory

Affected versions

PackageAffectedFixed in
Cursor
Product
< 1.31.3
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)

More Cursor advisories

All Cursor

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.