logo

AI-powered Cursor IDE vulnerable to prompt-injection attacks

ID: 6695bb09-0012-572a-a014-bccbde9d5ff8

STIX ID: report--6695bb09-0012-572a-a014-bccbde9d5ff8

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-08-01

Date Updated: 2026-07-18

Author: Ionut Ilascu

...
...

The report describes CurXecute (CVE-2025-54135), a prompt-injection flaw in the Cursor AI-powered IDE's Model Context Protocol (MCP) that allows attackers to inject and execute arbitrary commands by writing to the ~/.cursor/mcp.json configuration; Aim Security produced a proof-of-concept demonstrating attacker-controlled shells and warned of potential ransomware, data theft, and project corruption, and Cursor issued a patch in version 1.3 — users are advised to update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.