PT-2025-44994 · Cursor · Cursor

CVE-2025-64110

·

Published

2025-11-04

·

Updated

2025-12-01

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Cursor versions 1.7.23 and below
Description Cursor, a code editor built for programming with AI, contains a flaw where a malicious agent can access sensitive files that should be protected by the cursorignore mechanism. An attacker, having already gained prompt injection access or utilizing a malicious model, can create a new cursorignore file. This action overrides existing configurations, potentially allowing unauthorized reading of protected files.
Recommendations Update to version 2.0.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-64110
GHSA-VHC2-FJV4-WQCH

Affected Products

Cursor