CVE-2025-54135

Cursor Remote Code Execution Vulnerability (CVE-2025-54135)

August 7, 2025

Overview Recently, NSFOCUS CERT detected that Cursor issued a security bulletin and fixed the Cursor remote code execution vulnerability (CVE-2025-54135); Because Cursor allows files to be written to the workspace without user approval, when an external Model Control Protocol (MCP) server is configured through the Cursor user interface, an attacker can use Agent to rewrite […]

Search

Subscribe to the NSFOCUS Blog