PT-2025-45062 · Cursor · Cursor

CVE-2025-64108

·

Publicado

2025-11-04

·

Atualizado

2025-11-10

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cursor versions 1.7.44 and below
Description Cursor, a code editor for programming with AI, has an issue where NTFS path quirks can be exploited by an attacker to bypass file protections and overwrite files that normally require user confirmation. Successful modification of certain protected files could lead to Remote Code Execution (RCE). This requires chaining with a prompt injection or the attachment of a malicious model. The issue only affects systems that support the NTFS file system.
Recommendations Update to version 2.0.

Exploit

Correção

RCE

Path traversal

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-64108
GHSA-6R98-6QCW-RXRW

Produtos afetados

Cursor