PT-2025-34759 · Cursor · Cursor

Afine

·

Published

2025-08-26

·

Updated

2025-08-26

·

CVE-2025-9190

CVSS v4.0

4.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Cursor version 15.4.1
Description: The configuration of Cursor on macOS, specifically the "RunAsNode" fuse enabled, allows a local attacker with unprivileged access to execute arbitrary code that inherits Cursor TCC (Transparency, Consent, and Control) permissions. Acquired resource access is limited to previously granted permissions by the user. Accessing other resources beyond previously granted TCC permissions will prompt the user for approval in the name of Cursor, potentially disguising attacker's malicious intent.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2025-9190

Affected Products

Cursor