Code Editor Vulnerability in Cursor App by GetCursor
CVE-2025-32018

8.1HIGH

Key Information:

Vendor

Getcursor

Status
Vendor
CVE Published:
8 April 2025

What is CVE-2025-32018?

The Cursor app, a code editor developed by GetCursor, contains a vulnerability in versions 0.45.0 to 0.48.6 that allows the Cursor Agent to modify file paths outside of its intended workspace due to a regression. This issue occurs under specific circumstances when prompted by the user or through maliciously constructed input. While the agent could potentially write to unauthorized files, the UI displays the edited file consistently, making it likely for users to spot any unauthorized changes. This behavior makes real-world exploitation unlikely. The vulnerability has been addressed and fixed in version 0.48.7.

Affected Version(s)

cursor >= 0.45.0, < 0.48.7

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-32018 : Code Editor Vulnerability in Cursor App by GetCursor