CVE-2025-59944 is a critical vulnerability affecting Cursor IDE versions 1.6.23 and below, a code editor designed for AI programming. The flaw stems from case-sensitive checks in how Cursor protects sensitive configuration files, allowing attackers to modify these files via prompt injection on case-insensitive file systems. This can lead to full remote code execution (RCE) with a CVSS score of 9.8 (CRITICAL), indicating a network-exploitable vulnerability with low attack complexity and high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.6.23CPE matchmatch criteria | cpe:2.3:a:anysphere:cursor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.