Skip to content
CursorGHSA-6r98-6qcw-rxrw

Sensitive File Modification - NTFS Path Quirks

High8.8CVE-2025-64108 · Published Nov 3, 2025

### Summary Various NTFS path quirks allow a prompt injection attacker to circumvent sensitive file protections and overwrite files which Cursor requires human approval to overwrite. ### Details Short path and data stream syntax in NTFS paths can break Cursor's sensitive path detection, allowing an attacker to modify a protected file without Cursor asking for human approval. ### Impact Modification of some of the protected files can lead to RCE. Must be chained with a prompt injection or malicious model attach. Only affects systems supporting NTFS. ### Remediation Paths are now normalized for NTFS before guardrails are applied.

GitHub advisory

Affected versions

PackageAffectedFixed in
Cursor
Product
< 2.02.0
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)

More Cursor advisories

All Cursor
Advisory
Cursorignore Bypass via New Cursorignore Write
HighNov 3, 2025
Command Injection via Untrusted MCP Configuration in Cursor CLI Beta
High8.8Nov 3, 2025
Speedbump Modal Bypass in Cursor MCP Server Deep-Link
High8.8Nov 3, 2025
Sensitive File Protection Bypass - Path Manipulation Using Backslashes on Windows
High8.8Nov 3, 2025
Cursor CLI Agent - Sensitive File Overwrite Bypass
High7.1Oct 2, 2025
Cursor IDE - Sensitive File Overwrite Bypass
High8.0Oct 2, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.