CursorGHSA-x2vq-h6v6-jhc6
Cursor CLI Agent - Sensitive File Overwrite Bypass
High7.1CVE-2025-61593 · Published Oct 2, 2025
### Summary A vulnerability in the way Cursor CLI Agent protects its sensitive files (i.e. */.cursor/cli.json) allows attackers to modify the content of the files through prompt injection, thus achieving remote code execution. ### Impact A prompt injection can now lead to full RCE through modifying sensitive files on case-insensitive filesystems ### Remediations The sensitive file checks were fixed to respect the local filesystem.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Cursor CLI Product | < 2025.09.17-25b418f | 2025.09.17-25b418f |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-178
More Cursor advisories
All Cursor| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Nov 32025 | Sensitive File Protection Bypass - Path Manipulation Using Backslashes on Windows | High8.8 | 2.0 |
| Oct 22025 | Cursor IDE - Sensitive File Overwrite Bypass | High8.0 | 1.7 |
| Oct 22025 | Remote Code Execution in Cursor CLI via Cursor Agent MCP OAuth2 Communication | High8.8 | 2025.09.17-25b418f |
| Oct 22025 | Arbitrary code execution Permissive CLI Config in Cursor CLI | High8.8 | 2025.09.17-25b418f |
| Oct 22025 | RCE via .code-workspace files using Prompt Injection | High7.5 | 1.7 |
| Oct 22025 | Potential Information Leakage via Mermaid Diagram | Medium5.9 | 1.7 |