Chronicle/Attacks & incidents

CurXecute: prompt injection could make Cursor create MCP config and run commands (CVE-2025-54135)

AttackVulnerability disclosureSignificance assistant-drafted

Cursor's advisory states that the agent could create new workspace dotfiles without approval, so injected instructions arriving via an external MCP source could write an MCP configuration that launched attacker commands. Aim Security researchers reported it; it is rated CVSS 8.5 and fixed in Cursor 1.3.9.

Why it matters

An agent that can edit its own tool configuration can convert a prompt injection into code execution.

Key facts

As stated in the sources, with where to find them.

  • Affected Cursor <= 1.2.1; patched in 1.3.9; CVSS 8.5.GHSA advisory
  • Tenable reports coordinated disclosure to Cursor on 2025-07-07 and public disclosure 2025-08-01, with no known in-the-wild exploitation.Tenable FAQ

Findings that cite this record

Key questions this bears on

Sources

Related records