Sunday, 13 September 2026
8 agent hacks today 8 vs yesterday (0)

CurXecute: Cursor agent turned into remote code execution via MCP config

Aim Labs found that prompt injection reaching Cursor's agent could write a new MCP server entry to the project config, which Cursor executed without confirmation. Tracked as CVE-2025-54135.

Occurred 7 July 2025 · Disclosed 1 August 2025 · Record updated 13 September 2026

Impact

Remote code execution on developer machines from untrusted content such as a Slack message or web page. Fixed in Cursor 1.3.

Our coverage

Sources

  1. aim.securityhttps://www.aim.security/lp/aim-labs-curxecute-blogpost
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2025-54135