Skip to content
CursorGHSA-r22h-5wp2-2wfv

MCP Install Deeplink Did Not Show Arguments on User-Dialog

MediumCVE-2025-54133 · Published Aug 1, 2025

## Summary A UI information disclosure vulnerability in Cursor's MCP (Model Context Protocol) deeplink handler allows attackers to execute 2-click arbitrary system commands through social engineering attacks. When users click malicious `cursor://anysphere.cursor-deeplink/mcp/install` links, the installation dialog does not show the arguments being passed to the command being run. ## Impact If a user clicks a malicious deeplink, then examines the installation dialog (which did not show the arguments, but does show the command itself) and clicks through, the full command including the arguments will be executed on the machine. ## Remediation Displayed arguments in installation dialog.

GitHub advisory

Affected versions

PackageAffectedFixed in
Cursor
Product
< 1.31.3
Details and references

More Cursor advisories

All Cursor

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.