PT-2025-31701 · Cursor · Cursor

Qerogram

·

Published

2025-08-01

·

Updated

2025-08-02

·

CVE-2025-54133

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cursor versions 1.17 through 1.2
Description Cursor is a code editor built for programming with AI. A UI information disclosure exists in Cursor's MCP (Model Context Protocol) deeplink handler, enabling attackers to execute arbitrary system commands through social engineering attacks. Clicking malicious cursor://anysphere.cursor-deeplink/mcp/install links does not display the command arguments in the installation dialog. If a user clicks a malicious deeplink and proceeds with the installation, the full command, including arguments, will be executed on the machine.
Recommendations Update to version 1.3.

Exploit

Fix

OS Command Injection

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-54133
GHSA-R22H-5WP2-2WFV

Affected Products

Cursor