Skip to content
CursorGHSA-xcwh-rrwj-gxc7

Cursor IDE - Sensitive File Overwrite Bypass

High8.0CVE-2025-59944 · Published Oct 2, 2025

### Summary A set of case-sensitive checks in the way Cursor IDE protects its sensitive files (i.e. */.cursor/mcp.json) allows attackers to modify the content of the files through prompt injection, thus achieving remote code execution. ### Impact A prompt injection can now lead to full RCE through modifying sensitive files on case-insensitive fileystems ### Remediations The checks were changed to be case insensitive

GitHub advisory

Affected versions

PackageAffectedFixed in
Cursor
Product
< 1.71.7
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-178

More Cursor advisories

All Cursor
Advisory
Sensitive File Protection Bypass - Path Manipulation Using Backslashes on Windows
High8.8Nov 3, 2025
Cursor CLI Agent - Sensitive File Overwrite Bypass
High7.1Oct 2, 2025
Remote Code Execution in Cursor CLI via Cursor Agent MCP OAuth2 Communication
High8.8Oct 2, 2025
Arbitrary code execution Permissive CLI Config in Cursor CLI
High8.8Oct 2, 2025
RCE via .code-workspace files using Prompt Injection
High7.5Oct 2, 2025
Potential Information Leakage via Mermaid Diagram
Medium5.9Oct 2, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.