Skip to content
CursorGHSA-vhc2-fjv4-wqch

Cursorignore Bypass via New Cursorignore Write

HighCVE-2025-64110 · Published Nov 3, 2025

### Summary A logic bug in Cursor allows a malicious agent to read sensitive files that should be protected via cursorignore. An attacker who has already achieved prompt injection, or a malicious model, could create a new cursorignore file which can invalidate the configuration of pre-existing ones. This could allow a malicious agent to read protected files. ### Impact When chained with a successful prompt injection or malicious model, this bug allows the agent to bypass cursorignore protections and read protected files. If a user has non-default auto-run settings or is tricked via social engineering, this data could be exfiltrated from the machine. ### Remediation The agents ability to create and edit cursorignore files has been blocked in all cases.

GitHub advisory

Affected versions

PackageAffectedFixed in
Cursor
Product
< 2.02.0
Details and references

More Cursor advisories

All Cursor
Advisory
Command Injection via Untrusted MCP Configuration in Cursor CLI Beta
High8.8Nov 3, 2025
Speedbump Modal Bypass in Cursor MCP Server Deep-Link
High8.8Nov 3, 2025
Sensitive File Modification - NTFS Path Quirks
High8.8Nov 3, 2025
Sensitive File Protection Bypass - Path Manipulation Using Backslashes on Windows
High8.8Nov 3, 2025
Cursor CLI Agent - Sensitive File Overwrite Bypass
High7.1Oct 2, 2025
Cursor IDE - Sensitive File Overwrite Bypass
High8.0Oct 2, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.