Arbitrary Code Execution Vulnerability in Cursor Code Editor by Cursor Inc.
CVE-2025-54131

6.4MEDIUM

Key Information:

Vendor

Cursor

Status
Vendor
CVE Published:
1 August 2025

What is CVE-2025-54131?

An issue exists in the Cursor Code Editor where, in versions prior to 1.3, an attacker can circumvent the allow list in auto-run mode, allowing for arbitrary command execution. This exploit can occur when users have configured the editor to operate under an allowlist regime instead of requiring explicit approval for each terminal call. Attackers may exploit this vulnerability in conjunction with indirect prompt injection techniques, enabling unauthorized commands to be executed without user consent. This vulnerability has been remediated in version 1.3 of the product.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

cursor < 1.3

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.