Vulnerabilities in cursor
28 resultsVexday analysis
A base Vexday registra 25 vulnerabilidades no Cursor, com 3 classificadas como críticas, mas nenhuma sob ataque ativo documentado até o momento. A fraqueza dominante é CWE-78 (injeção de comando), padrão de risco significativo em ferramentas de desenvolvimento; das 25, 4 foram publicadas nos últimos 90 dias, indicando exposição recente moderada que merece monitoramento contínuo.
CVE-2025-54136HIGHCursor's Modification of MCP Server Definitions Bypasses Manual Re-approvalsEPSS 26.1%CVE-2025-54135HIGHCursor Agent is vulnerable to prompt injection via MCP Special FilesEPSS 1.7%CVE-2025-62354CRITICALImproper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized attacker to executeEPSS 1.4%CVE-2026-50549CRITICALCursor Desktop sandbox escape via symlink and failed path canonicalizationEPSS 1.3%CVE-2025-61591HIGHCursor CLI's Cursor Agent MCP OAuth2 Communication is Vulnerable to Remote Code ExecutionEPSS 1.1%CVE-2026-50548CRITICALCursor Desktop sandbox escape via agent-controlled working directoryEPSS 1.0%CVE-2026-26268HIGHCursor sandbox escape via Git hooksEPSS 0.7%CVE-2026-22708HIGHCursor has a Terminal Tool Allowlist Bypass via Environment VariablesEPSS 0.5%CVE-2025-61590HIGHCursor is vulnerable to RCE via .code-workspace files using Prompt InjectionEPSS 0.5%CVE-2025-64109HIGHCursor CLI Beta: Command Injection via Untrusted MCP ConfigurationEPSS 0.5%CVE-2025-54131MEDIUMCursor bypasses its allow list to execute arbitrary commandsEPSS 0.5%CVE-2025-64108HIGHCursor's Sensitive File Modification can Lead to NTFS Path QuirksEPSS 0.5%CVE-2025-61592HIGHCursor CLI: Arbitrary Code Execution Possible through Permissive CLI ConfigEPSS 0.4%CVE-2026-61613HIGHCursor: Cloud Agent Browser Sandbox EscapeEPSS 0.4%CVE-2025-61593HIGHCursor CLI Agent: Sensitive File Overwrite BypassEPSS 0.4%CVE-2025-64106HIGHCursor: Speedbump Modal Bypass in MCP Server Deep-LinkEPSS 0.4%CVE-2025-54133MEDIUMCursor's MCP Install Deeplink Does Not Show Arguments in its User-DialogEPSS 0.4%CVE-2025-64110HIGHCursor: Authentication Bypass Possible via New Cursorignore WriteEPSS 0.4%CVE-2025-59944HIGHCursor IDE: Sensitive File Overwrite Bypass is PossibleEPSS 0.4%CVE-2025-64107HIGHCursor is Vulnerable to Path Manipulation Using Backslashes on WindowsEPSS 0.4%