MCP Install Deeplink Did Not Show Arguments on User-Dialog
MediumCVE-2025-54133 · Published Aug 1, 2025
## Summary A UI information disclosure vulnerability in Cursor's MCP (Model Context Protocol) deeplink handler allows attackers to execute 2-click arbitrary system commands through social engineering attacks. When users click malicious `cursor://anysphere.cursor-deeplink/mcp/install` links, the installation dialog does not show the arguments being passed to the command being run. ## Impact If a user clicks a malicious deeplink, then examines the installation dialog (which did not show the arguments, but does show the command itself) and clicks through, the full command including the arguments will be executed on the machine. ## Remediation Displayed arguments in installation dialog.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Cursor Product | < 1.3 | 1.3 |
Details and references
- Severity from
- GitHub (reviewed advisory)
More Cursor advisories
All Cursor| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 22025 | Arbitrary code execution from Cursor Agent through a prompt injection via MCP Special Files | High8.5 | 1.3.9 |
| Aug 22025 | Arbitrary code execution from Cursor Agent through a prompt injection via Editor Special Files | High7.5 | 1.3.9 |
| Aug 12025 | Bypassing allow list to execute an arbitrary command | Medium6.4 | 1.3 |
| Aug 12025 | Arbitrary Image Fetch in Mermaid Diagram Tool | Medium4.4 | 1.3 |
| Aug 12025 | Modification of MCP Server Definitions Bypasses Manual Re-approval | High7.2 | 1.3 |
| Jun 192025 | IDOR in Usage API Leading to Unauthorized Data Exposure | Medium4.3 | 2025-06-17 |