{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/cursor-mcpoison-cve-2025-54136-2025/",
 "asOf": "2026-09-26",
 "id": "cursor-mcpoison-cve-2025-54136-2025",
 "date": "2025-08-05",
 "datePrecision": "day",
 "title": "MCPoison: Cursor trusted approved MCP configs even after their commands changed (CVE-2025-54136)",
 "lane": "attack",
 "kind": "vulnerability-disclosure",
 "summary": "Check Point Research found that Cursor bound MCP approval to a configuration's name rather than its contents, so a collaborator with repository write access could swap an approved harmless command for a malicious one that ran on each project open. Cursor 1.3, released 2025-07-29, prompts for approval on any MCP configuration change.",
 "whyItMatters": "Approval that does not follow content changes becomes a persistence mechanism in shared repositories.",
 "actors": [
  "check-point",
  "cursor"
 ],
 "topics": [
  "tool-and-mcp-security",
  "agent-supply-chain"
 ],
 "atlas": [
  "tools",
  "supply-chain",
  "human-approver"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://research.checkpoint.com/2025/cursor-vulnerability-mcpoison/",
   "publisher": "Check Point Research",
   "title": "CVE-2025-54136 – MCPoison Cursor IDE: Persistent Code Execution via MCP Trust Bypass",
   "date": "2025-08-05",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "Reported 2025-07-16; fixed in Cursor 1.3 on 2025-07-29.",
   "locator": "Disclosure timeline"
  },
  {
   "fact": "Tenable lists CVSS 7.2.",
   "locator": "Tenable FAQ (see CurXecute record)"
  }
 ],
 "significance": 3,
 "fideQuestions": [
  "FID-076"
 ],
 "methods": [
  "human-approval",
  "tool-poisoning"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}