When Public Prompts Turn Into Local Shells: ‘CurXecute’ – RCE in Cursor via MCP Auto‑Start
ID: 6fed02f4-887e-5278-af1e-119b3cdb2690
STIX ID: report--6fed02f4-887e-5278-af1e-119b3cdb2690
Feed Name: Cato Networks
Aim Labs disclosed a high-severity vulnerability dubbed “CurXecute” (CVE-2025-54135) in Cursor IDE that allows remote-code-execution by poisoning Model Context Protocol (MCP) inputs; Cursor auto-executes changes to ~/.cursor/mcp.json and applies suggested edits live (before user approval), enabling an attacker who can supply external content (e.g., a crafted Slack message) to run arbitrary commands under the user’s privileges. The issue carries an 8.6 severity, was reported to Cursor in July 2025, and was patched in v1.3, while earlier releases remain vulnerable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
