PT-2025-40459 · Mermaid+1 · Mermaid+1

Maccarita

+1

·

Published

2025-10-03

·

Updated

2025-10-20

·

CVE-2025-61589

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cursor versions 1.6 and below
Description Cursor, a code editor for programming with AI, has an issue where Mermaid, used for rendering diagrams, allows embedding images. This can be exploited to exfiltrate sensitive information to a third-party attacker-controlled server through an image fetch, following a successful prompt injection. A malicious model or backdoor could also trigger this exploit. The issue requires prompt injection from malicious data such as web content, image uploads, or source code to be successfully exploited. The image fetch mechanism is used to transmit data to an external server controlled by the attacker.
Recommendations Update to version 1.7 or later.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-61589
GHSA-43WJ-MWCC-X93P
GHSA-XW2X-252G-97W2

Affected Products

Cursor
Mermaid