Cursor是Cursor开源的一个 AI 代码编辑器。 Cursor 1.17至1.2版本存在操作系统命令注入漏洞,该漏洞源于MCP深链接处理程序存在信息泄露,可能导致任意系统命令执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-54136 | 7.2 HIGH | Cursor's Modification of MCP Server Definitions Bypasses Manual Re-approvals |
| CVE-2025-54131 | 6.4 MEDIUM | Cursor bypasses its allow list to execute arbitrary commands |
| CVE-2025-54132 | 4.4 MEDIUM | Cursor's Mermaid Diagram Tool is Vulnerable to an Arbitrary Image Fetch |
No comments yet