CVE-2025-64110: Cursor: Authentication Bypass Possible via New Cursorignore Write
Cursor is a code editor built for programming with AI. In versions 1.7.23 and below, a logic bug allows a malicious agent to read sensitive files that should be protected via cursorignore. An attacker who has already achieved prompt injection, or a malicious model, could create a new cursorignore file which can invalidate the configuration of pre-existing ones. This could allow a malicious agent to read protected files. This issue is fixed in version 2.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64110?
CVE-2025-64110 has been classified with a severity level that indicates a moderate risk due to its logic bug allowing unauthorized file access.
How do I fix CVE-2025-64110?
To mitigate CVE-2025-64110, upgrade to Cursor version 1.7.24 or later which addresses the vulnerability.
What are the potential impacts of CVE-2025-64110?
CVE-2025-64110 can allow an attacker to read sensitive files that should be protected, leading to a potential data breach.
Who is affected by CVE-2025-64110?
All users of Cursor versions 1.7.23 and below are affected by CVE-2025-64110.
What should I do if I'm unable to update my software to fix CVE-2025-64110?
If unable to update, it is advised to restrict access and monitor for any suspicious activities related to your Cursor installation.