CVE-2025-54135: Cursor Agent is vulnerable to prompt injection via MCP Special Files
Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions below 1.3.9, If the file is a dotfile, editing it requires approval but creating a new one doesn't. Hence, if sensitive MCP files, such as the .cursor/mcp.json file don't already exist in the workspace, an attacker can chain a indirect prompt injection vulnerability to hijack the context to write to the settings file and trigger RCE on the victim without user approval. This is fixed in version 1.3.9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54135?
CVE-2025-54135 has a high severity due to its ability to allow unauthorized file creation without user consent.
How do I fix CVE-2025-54135?
To fix CVE-2025-54135, update Cursor to version 1.3.9 or later.
What impact does CVE-2025-54135 have on my data?
CVE-2025-54135 can lead to the creation of sensitive files without user awareness, potentially compromising data security.
Who is affected by CVE-2025-54135?
Users of Cursor versions below 1.3.9 are affected by CVE-2025-54135.
Can I mitigate CVE-2025-54135 without updating?
Mitigation options are limited, and the best practice is to promptly update to the latest version of Cursor.