CVE-2025-49150: Cursor Agent Potentially Leaks Information using JSON schema

Published Jun 11, 2025
·
Updated

Cursor is a code editor built for programming with AI. Prior to 0.51.0, by default, the setting json.schemaDownload.enable was set to True. This means that by writing a JSON file, an attacker can trigger an arbitrary HTTP GET request that does not require user confirmation. Since the Cursor Agent can edit JSON files, this means a malicious agent, for example, after a prompt injection attack already succeeded, could trigger a GET request to an attacker controlled URL, potentially exfiltrating other data the agent may have access to. This vulnerability is fixed in 0.51.0.

Affected Software

1 affected component
Cursor Cursor Agent<0.51.0

Event History

Jun 11, 2025
CVE Published
via MITRE·05:49 PM
Data Sourced
via MITRE·05:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2025-49150?

CVE-2025-49150 has a high severity level due to the potential for arbitrary HTTP GET requests when manipulating JSON files.

2

How can I fix CVE-2025-49150?

To fix CVE-2025-49150, update to Cursor version 0.51.0 or later where the json.schemaDownload.enable setting is disabled by default.

3

Who is affected by CVE-2025-49150?

Users of Cursor Agent versions prior to 0.51.0 are affected by CVE-2025-49150 due to the default settings allowing unsafe file operations.

4

What type of attack is associated with CVE-2025-49150?

CVE-2025-49150 is associated with a vulnerability that allows attackers to perform arbitrary HTTP GET requests without user confirmation.

5

Is there a workaround for CVE-2025-49150 before upgrading?

As a workaround for CVE-2025-49150, users can manually change the json.schemaDownload.enable setting to False until they can upgrade.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203