{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/cursor-curxecute-cve-2025-54135-2025/",
 "asOf": "2026-09-26",
 "id": "cursor-curxecute-cve-2025-54135-2025",
 "date": "2025-08-01",
 "datePrecision": "day",
 "title": "CurXecute: prompt injection could make Cursor create MCP config and run commands (CVE-2025-54135)",
 "lane": "attack",
 "kind": "vulnerability-disclosure",
 "summary": "Cursor's advisory states that the agent could create new workspace dotfiles without approval, so injected instructions arriving via an external MCP source could write an MCP configuration that launched attacker commands. Aim Security researchers reported it; it is rated CVSS 8.5 and fixed in Cursor 1.3.9.",
 "whyItMatters": "An agent that can edit its own tool configuration can convert a prompt injection into code execution.",
 "actors": [
  "aim-security",
  "cursor"
 ],
 "topics": [
  "prompt-injection",
  "tool-and-mcp-security",
  "sandbox-containment"
 ],
 "atlas": [
  "untrusted-content",
  "tools",
  "sandbox"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://github.com/cursor/cursor/security/advisories/GHSA-4cxx-hrm3-49rm",
   "publisher": "Cursor (GitHub Security Advisory)",
   "title": "Cursor Agent arbitrary code execution (CVE-2025-54135)",
   "date": "2025-08-02",
   "type": "primary",
   "accessed": "2026-09-25"
  },
  {
   "url": "https://www.tenable.com/blog/faq-cve-2025-54135-cve-2025-54136-vulnerabilities-in-cursor-curxecute-mcpoison",
   "publisher": "Tenable",
   "title": "CVE-2025-54135, CVE-2025-54136: Frequently Asked Questions About Vulnerabilities in Cursor IDE (CurXecute and MCPoison)",
   "date": "2025-08-05",
   "type": "secondary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "Affected Cursor <= 1.2.1; patched in 1.3.9; CVSS 8.5.",
   "locator": "GHSA advisory"
  },
  {
   "fact": "Tenable reports coordinated disclosure to Cursor on 2025-07-07 and public disclosure 2025-08-01, with no known in-the-wild exploitation.",
   "locator": "Tenable FAQ"
  }
 ],
 "significance": 3,
 "fideQuestions": [],
 "methods": [
  "approval-bypass",
  "indirect-prompt-injection"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}