PT-2025-40600 · Unknown · Cursor Ide

·

CVE-2025-59944

·

Published

2025-10-03

·

Updated

2026-06-09

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cursor versions 1.6.23 and below
Description Cursor IDE has case-sensitive checks when protecting sensitive files, such as /.cursor/mcp.json. This allows attackers to modify these files through prompt injection, potentially leading to remote code execution (RCE). This is possible on case-insensitive file systems. A prompt injection can result in full RCE by modifying sensitive files.
Recommendations Update to version 1.7 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-59944
GHSA-XCWH-RRWJ-GXC7

Affected Products

Cursor Ide