CVE-2025-54135 is a critical vulnerability affecting Cursor, an AI-powered code editor, in versions below 1.3.9. It allows unapproved writing to in-workspace files, specifically sensitive configuration files like .cursor/mcp.json, through a chained indirect prompt injection. This enables attackers to hijack the context, modify settings, and achieve Remote Code Execution (RCE) without user interaction. The vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered significant community attention with 18 mentions and 4 media articles, indicating high awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.9CPE matchmatch criteria | cpe:2.3:a:anysphere:cursor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.