logo

When Public Prompts Turn Into Local Shells: ‘CurXecute’ – RCE in Cursor via MCP Auto‑Start

ID: 6fed02f4-887e-5278-af1e-119b3cdb2690

STIX ID: report--6fed02f4-887e-5278-af1e-119b3cdb2690

Feed Name: Cato Networks

Threat Score
78/100

Date Published: 2025-01-08

Date Updated: 2026-07-23

Author: Ofir Abu

...
...

Aim Labs disclosed a high-severity vulnerability dubbed “CurXecute” (CVE-2025-54135) in Cursor IDE that allows remote-code-execution by poisoning Model Context Protocol (MCP) inputs; Cursor auto-executes changes to ~/.cursor/mcp.json and applies suggested edits live (before user approval), enabling an attacker who can supply external content (e.g., a crafted Slack message) to run arbitrary commands under the user’s privileges. The issue carries an 8.6 severity, was reported to Cursor in July 2025, and was patched in v1.3, while earlier releases remain vulnerable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.