Check Point Research found that Cursor bound MCP approval to a configuration's name rather than its contents, so a collaborator with repository write access could swap an approved harmless command for a malicious one that ran on each project open. Cursor 1.3, released 2025-07-29, prompts for approval on any MCP configuration change.
Why it matters
Approval that does not follow content changes becomes a persistence mechanism in shared repositories.
Key facts
As stated in the sources, with where to find them.
- Reported 2025-07-16; fixed in Cursor 1.3 on 2025-07-29.Disclosure timeline
- Tenable lists CVSS 7.2.Tenable FAQ (see CurXecute record)
Findings that cite this record
Key questions this bears on
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
- Can AI agents defend and oversee systems on their own?Not yet. Agents are weak on realistic defensive benchmarks and monitors can be evaded; assistants help analysts who stay in charge.
Sources
Related records
Sep 25, 2025
Jul 9, 2025
Feb 25, 2026
Apr 1, 2025
Mar 30, 2025
Apr 15, 2026