Code Injection Vulnerability in Cursor by Cursor
CVE-2025-61589
5.9MEDIUM
What is CVE-2025-61589?
In Cursor, a code editor designed for programming with AI, versions 1.6 and below contain a vulnerability that allows for sensitive data exfiltration through a prompt injection. By leveraging the capability of Mermaid for rendering diagrams, an attacker can embed images linked to third-party servers. If the embedded image is fetched, it can lead to unauthorized transmission of sensitive information to an external server controlled by an attacker. The exploit hinges on malicious data, including web sources, image uploads, or compromised source code. This issue has been addressed in version 1.7, but additional bypasses were identified after the initial mitigation.
Affected Version(s)
cursor < 1.7