Cursorignore Bypass via New Cursorignore Write
HighCVE-2025-64110 · Published Nov 3, 2025
### Summary A logic bug in Cursor allows a malicious agent to read sensitive files that should be protected via cursorignore. An attacker who has already achieved prompt injection, or a malicious model, could create a new cursorignore file which can invalidate the configuration of pre-existing ones. This could allow a malicious agent to read protected files. ### Impact When chained with a successful prompt injection or malicious model, this bug allows the agent to bypass cursorignore protections and read protected files. If a user has non-default auto-run settings or is tricked via social engineering, this data could be exfiltrated from the machine. ### Remediation The agents ability to create and edit cursorignore files has been blocked in all cases.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Cursor Product | < 2.0 | 2.0 |
Details and references
- Severity from
- GitHub (reviewed advisory)
More Cursor advisories
All Cursor| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Nov 32025 | Command Injection via Untrusted MCP Configuration in Cursor CLI Beta | High8.8 | 2025.09.17-25b418f |
| Nov 32025 | Speedbump Modal Bypass in Cursor MCP Server Deep-Link | High8.8 | 2.0 |
| Nov 32025 | Sensitive File Modification - NTFS Path Quirks | High8.8 | 2.0 |
| Nov 32025 | Sensitive File Protection Bypass - Path Manipulation Using Backslashes on Windows | High8.8 | 2.0 |
| Oct 22025 | Cursor CLI Agent - Sensitive File Overwrite Bypass | High7.1 | 2025.09.17-25b418f |
| Oct 22025 | Cursor IDE - Sensitive File Overwrite Bypass | High8.0 | 1.7 |