Aug 1, 2025
CurXecute: prompt injection could make Cursor create MCP config and run commands (CVE-2025-54135)
Cursor's advisory states that the agent could create new workspace dotfiles without approval, so injected instructions arriving via an external MCP source could write an MCP configuration that launched attacker commands. Aim Security researchers reported it; it is rated CVSS 8.5 and fixed in Cursor 1.3.9.