Code Injection Vulnerability in Cursor by Cursor
CVE-2025-61589

5.9MEDIUM

Key Information:

Vendor

Cursor

Status
Vendor
CVE Published:
3 October 2025

What is CVE-2025-61589?

In Cursor, a code editor designed for programming with AI, versions 1.6 and below contain a vulnerability that allows for sensitive data exfiltration through a prompt injection. By leveraging the capability of Mermaid for rendering diagrams, an attacker can embed images linked to third-party servers. If the embedded image is fetched, it can lead to unauthorized transmission of sensitive information to an external server controlled by an attacker. The exploit hinges on malicious data, including web sources, image uploads, or compromised source code. This issue has been addressed in version 1.7, but additional bypasses were identified after the initial mitigation.

Affected Version(s)

cursor < 1.7

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-61589 : Code Injection Vulnerability in Cursor by Cursor