CVE 8.8 HIGH

Cursor is Vulnerable to Path Manipulation Using Backslashes on Windows_CVE-2025-64107

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

Cursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may lead to RCE. Cursor detects path manipulation via forward slashes (./.cursor/./././././mcp.json etc.), and requires human approval to complete the operation. However, the same kind of manipulation using backslashes was not correctly detected, allowing an attacker who had already achieved prompt injection or some other level of control to overwrite sensitive editor files without approval on Windows machines. This issue is fixed in version 2.0.

AI Analysis

Path manipulation vulnerability using backslashes on Windows machines, allowing for RCE in versions 1.7.52 and below

Basic Information

ID CVE-2025-64107
Source GitHub_M
Published Nov 4, 2025 at 22:51

Affected Product

Vendor cursor
Product cursor
Version < 2.0
Affected Versions cursor cursor < 2.0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor Cursor
Product Cursor Code Editor
Version 1.7.52 and below

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.