PT-2025-31700 · Mermaid +1 · Mermaid +1

Wunderwuzzi23

·

Published

2025-08-01

·

Updated

2025-08-02

·

CVE-2025-54132

CVSS v3.1
4.4
VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

Name of the Vulnerable Software and Affected Versions:

Cursor versions prior to 1.3

Description:

Cursor is a code editor built for programming with AI. Versions prior to 1.3 allow embedding images through Mermaid, a diagram rendering tool. This can be exploited to exfiltrate sensitive information to a third-party attacker-controlled server via an image fetch following a successful prompt injection. A malicious model or backdoor could also trigger this exploit. The issue requires prompt injection from malicious data (web, image upload, source code) to function.

Recommendations:

Update to version 1.3 or later.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-54132

Affected Products

Cursor
Mermaid