Remote Code Execution in Cursor Code Editor Versions Prior to 1.8
CVE-2025-61592
8.8HIGH
What is CVE-2025-61592?
Cursor, an AI-enabled code editor, is susceptible to a Remote Code Execution flaw in versions 1.7 and earlier. The vulnerability arises from the automatic loading of CLI configuration files from the working directory, potentially allowing attackers to bypass global settings. Users running the CLI within malicious repositories may unintentionally execute harmful shell commands facilitated by manipulated project-specific rules. Immediate patching (version 2025.09.17-25b418f) is essential to safeguard against these exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
cursor <= 1.7
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
