CVE 6.4 MEDIUM

Cursor bypasses its allow list to execute arbitrary commands_CVE-2025-54131

6.4 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H

Description

Cursor is a code editor built for programming with AI. In versions below 1.3, an attacker can bypass the allow list in auto-run mode with a backtick (`) or $(cmd). If a user has swapped Cursor from its default settings (requiring approval for every terminal call) to an allowlist, an attacker can execute arbitrary command execution outside of the allowlist without user approval. An attacker can trigger this vulnerability if chained with indirect prompt injection. This is fixed in version 1.3.

Basic Information

ID CVE-2025-54131
Source GitHub_M
Published Aug 1, 2025 at 23:05
Modified Aug 4, 2025 at 13:57

Affected Product

Vendor cursor
Product cursor
Version < 1.3
Affected Versions cursor cursor < 1.3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.