PT-2025-45060 · Cursor · Cursor

Published

2025-11-04

·

Updated

2025-11-05

·

CVE-2025-64106

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cursor versions 1.7.28 and below
Description Cursor is a code editor designed for programming with AI. An input validation issue within Cursor’s MCP server installation allows maliciously crafted deep-links to circumvent standard security warnings. This can conceal executed commands from users who accept the server connection. If a user navigates to a malicious deep-link provided by an attacker, they may not see the expected security prompt and, upon acceptance, will execute commands specified within the deep-link. The affected component is the deep-link processing mechanism.
Recommendations Versions prior to 1.7.28 should be updated.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-64106
GHSA-4575-FH42-7848

Affected Products

Cursor