Chronicle/Attacks & incidents

MCPoison: Cursor trusted approved MCP configs even after their commands changed (CVE-2025-54136)

AttackVulnerability disclosureSignificance assistant-drafted

Check Point Research found that Cursor bound MCP approval to a configuration's name rather than its contents, so a collaborator with repository write access could swap an approved harmless command for a malicious one that ran on each project open. Cursor 1.3, released 2025-07-29, prompts for approval on any MCP configuration change.

Why it matters

Approval that does not follow content changes becomes a persistence mechanism in shared repositories.

Key facts

As stated in the sources, with where to find them.

  • Reported 2025-07-16; fixed in Cursor 1.3 on 2025-07-29.Disclosure timeline
  • Tenable lists CVSS 7.2.Tenable FAQ (see CurXecute record)

Findings that cite this record

Key questions this bears on

Sources

Related records