PT-2025-44994 · Cursor · Cursor

Published

2025-11-04

·

Updated

2025-12-01

·

CVE-2025-64110

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Cursor versions 1.7.23 and below
Description Cursor, a code editor built for programming with AI, contains a flaw where a malicious agent can access sensitive files that should be protected by the cursorignore mechanism. An attacker, having already gained prompt injection access or utilizing a malicious model, can create a new cursorignore file. This action overrides existing configurations, potentially allowing unauthorized reading of protected files.
Recommendations Update to version 2.0.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-64110
GHSA-VHC2-FJV4-WQCH

Affected Products

Cursor