Sensitive File Modification - NTFS Path Quirks Severity High (8.8/10) Package Cursor Affected Versions 1.7.44 Patched Versions 2.0 Summary Various NTFS path quirks allow a prompt injection attacker to circumvent sensitive file protections and overwrite files which Cursor requires human approval to overwrite. Details Short path and data stream syntax in NTFS paths can break Cursor's sensitive path detection, allowing an attacker to modify a protected file without Cursor asking for human approval. Impact Modification of some of the protected files can lead to RCE. Must be chained with a prompt injection or malicious model attach. Only affects systems supporting NTFS. Remediation Paths are now normalized for NTFS before guardrails are applied. CVSS v3 Base Metrics Attack Vector: Network Attack Complexity: Low Privileges Required: Low User Interaction: None Scope: Unchanged Confidentiality: High Integrity: High Availability: High CVE ID CVE-2025-64108 Credited Reporter Philt