Remote Code Execution in Cursor Code Editor Versions Prior to 1.8
CVE-2025-61592
8.8HIGH
What is CVE-2025-61592?
Cursor, an AI-enabled code editor, is susceptible to a Remote Code Execution flaw in versions 1.7 and earlier. The vulnerability arises from the automatic loading of CLI configuration files from the working directory, potentially allowing attackers to bypass global settings. Users running the CLI within malicious repositories may unintentionally execute harmful shell commands facilitated by manipulated project-specific rules. Immediate patching (version 2025.09.17-25b418f) is essential to safeguard against these exploits.
Affected Version(s)
cursor <= 1.7
