Cursor's advisory states that the agent could create new workspace dotfiles without approval, so injected instructions arriving via an external MCP source could write an MCP configuration that launched attacker commands. Aim Security researchers reported it; it is rated CVSS 8.5 and fixed in Cursor 1.3.9.
Why it matters
An agent that can edit its own tool configuration can convert a prompt injection into code execution.
Key facts
As stated in the sources, with where to find them.
- Affected Cursor <= 1.2.1; patched in 1.3.9; CVSS 8.5.GHSA advisory
- Tenable reports coordinated disclosure to Cursor on 2025-07-07 and public disclosure 2025-08-01, with no known in-the-wild exploitation.Tenable FAQ
Findings that cite this record
Jul 28, 2025
Jul 28, 2025
Key questions this bears on
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
Sources
Related records
May 7, 2026
Jul 1, 2026
Aug 12, 2025
Aug 6, 2025
Aug 6, 2025
Jul 28, 2025