Skip to content
CursorGHSA-wj33-264c-j9cq

Remote Code Execution in Cursor CLI via Cursor Agent MCP OAuth2 Communication

High8.8CVE-2025-61591 · Published Oct 2, 2025

### Summary In the latest version of Cursor Agent CLI, when MCP uses OAuth authentication with an untrusted MCP server, an attacker can impersonate a malicious MCP server and return crafted, maliciously injected commands during the interaction process, leading to command injection and potential remote code execution. ### Impact If chained with an untrusted MCP service via OAuth, this command injection vulnerability could allow arbitrary code execution on the host by the agent. This can then be used to directly compromise the system by executing malicious commands with full user privileges. ### Remediation Fixed the command injection site.

GitHub advisory

Affected versions

PackageAffectedFixed in
Cursor CLI
Product
< 2025.09.17-25b418f2025.09.17-25b418f
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-78

More Cursor advisories

All Cursor
Advisory
Sensitive File Protection Bypass - Path Manipulation Using Backslashes on Windows
High8.8Nov 3, 2025
Cursor CLI Agent - Sensitive File Overwrite Bypass
High7.1Oct 2, 2025
Cursor IDE - Sensitive File Overwrite Bypass
High8.0Oct 2, 2025
Arbitrary code execution Permissive CLI Config in Cursor CLI
High8.8Oct 2, 2025
RCE via .code-workspace files using Prompt Injection
High7.5Oct 2, 2025
Potential Information Leakage via Mermaid Diagram
Medium5.9Oct 2, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.