PT-2025-31702 · Cursor · Cursor
Chaandrey
·
Published
2025-07-29
·
Updated
2026-05-24
·
CVE-2025-54136
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cursor versions 1.2.4 and earlier
Description
Cursor is a code editor designed for AI-assisted programming. A flaw, dubbed MCPoison (CVE-2025-54136), allows attackers to achieve remote and persistent code execution. This is accomplished by modifying a trusted MCP (Model Context Protocol) configuration file within a shared GitHub repository or directly on the target machine. Once a user approves a harmless MCP, an attacker can silently replace it with a malicious command, such as
calc.exe, without any warnings or prompts. If an attacker gains write access to a user's active branches in a source repository containing existing MCP servers, or obtains arbitrary file-write access locally, they can execute arbitrary code. The issue stems from a blind trust in MCP servers and a lack of basic security measures. The vulnerability allows for silent compromise by modifying a previously trusted configuration file.Recommendations
Update to version 1.3 or later to address this vulnerability.
Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cursor