Cursor could be turned into remote code execution with one message
Prompt injection let researchers write to the IDE's MCP configuration, which Cursor then ran without asking. Version 1.3 closed the hole.
2 Aug 2025
Aim Labs found that prompt injection reaching Cursor's agent could write a new MCP server entry to the project config, which Cursor executed without confirmation. Tracked as CVE-2025-54135.
Occurred 7 July 2025 · Disclosed 1 August 2025 · Record updated 13 September 2026
Remote code execution on developer machines from untrusted content such as a Slack message or web page. Fixed in Cursor 1.3.
Prompt injection let researchers write to the IDE's MCP configuration, which Cursor then ran without asking. Version 1.3 closed the hole.
2 Aug 2025