PT-2025-40542 · Cursor · Cursor

Alonza

·

Published

2025-10-03

·

Updated

2025-10-03

·

CVE-2025-61593

CVSS v3.1
7.1
VectorAV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cursor versions 1.7 and below
Description Cursor CLI Agent does not adequately protect its sensitive files, specifically */.cursor/cli.json. This allows attackers to modify the content of these files through prompt injection, potentially leading to remote code execution (RCE). A prompt injection can result in full RCE by modifying sensitive files on case-insensitive filesystems.
Recommendations Update to a version later than 1.7.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-61593

Affected Products

Cursor