CVE-2025-61593: Cursor CLI Agent: Sensitive File Overwrite Bypass
Cursor is a code editor built for programming with AI. In versions 1.7 and below, a vulnerability in the way Cursor CLI Agent protects its sensitive files (i.e. /.cursor/cli.json) allows attackers to modify the content of the files through prompt injection, thus achieving remote code execution. A prompt injection can lead to full RCE through modifying sensitive files on case-insensitive filesystems. This issue is fixed in a commit, 25b418f, but has yet to be released as of October 3, 2025.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61593?
CVE-2025-61593 is considered a high severity vulnerability due to its potential for remote code execution via prompt injection.
How do I fix CVE-2025-61593?
To mitigate CVE-2025-61593, upgrade the Cursor CLI Agent to version 1.8 or later.
What versions are affected by CVE-2025-61593?
CVE-2025-61593 affects all versions of Cursor CLI Agent up to and including 1.7.
What kind of attack does CVE-2025-61593 facilitate?
CVE-2025-61593 facilitates prompt injection attacks that can modify sensitive files in the Cursor CLI Agent.
Is there a timeline for a fix for CVE-2025-61593?
A fix for CVE-2025-61593 is available in version 1.8 and later of the Cursor CLI Agent.