CVE-2025-27554: Code Injection
ToDesktop before 2024-10-03, as used by Cursor before 2024-10-03 and other applications, allows remote attackers to execute arbitrary commands on the build server (e.g., read secrets from the desktopify config.prod.json file), and consequently deploy updates to any app, via a postinstall script in package.json. No exploitation occurred.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27554?
CVE-2025-27554 has a high severity as it allows remote attackers to execute arbitrary commands on the affected build servers.
How do I fix CVE-2025-27554?
To fix CVE-2025-27554, upgrade ToDesktop or Cursor to the latest version released after October 3, 2024.
What applications are affected by CVE-2025-27554?
CVE-2025-27554 affects ToDesktop before version 2024-10-03 and Cursor before version 2024-10-03.
What can attackers do with CVE-2025-27554?
Attackers exploiting CVE-2025-27554 can deploy updates to any app and access sensitive information like secrets from the configuration file.
When was CVE-2025-27554 discovered?
CVE-2025-27554 was identified before October 3, 2024.