PT-2025-31701 · Cursor · Cursor

Qerogram

·

Publicado

2025-08-01

·

Atualizado

2025-08-02

·

CVE-2025-54133

CVSS v3.1

9.6

Crítica

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cursor versions 1.17 through 1.2
Description Cursor is a code editor built for programming with AI. A UI information disclosure exists in Cursor's MCP (Model Context Protocol) deeplink handler, enabling attackers to execute arbitrary system commands through social engineering attacks. Clicking malicious cursor://anysphere.cursor-deeplink/mcp/install links does not display the command arguments in the installation dialog. If a user clicks a malicious deeplink and proceeds with the installation, the full command, including arguments, will be executed on the machine.
Recommendations Update to version 1.3.

Exploit

Correção

OS Command Injection

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-54133
GHSA-R22H-5WP2-2WFV

Produtos afetados

Cursor