Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-54133

Опубликовано: 02 авг. 2025
Источник: nvd
CVSS3: 9.6
EPSS Низкий

Описание

Cursor is a code editor built for programming with AI. In versions 1.17 through 1.2, there is a UI information disclosure vulnerability in Cursor's MCP (Model Context Protocol) deeplink handler, allowing attackers to execute 2-click arbitrary system commands through social engineering attacks. When users click malicious cursor://anysphere.cursor-deeplink/mcp/install links, the installation dialog does not show the arguments being passed to the command being run. If a user clicks a malicious deeplink, then examines the installation dialog and clicks through, the full command including the arguments will be executed on the machine. This is fixed in version 1.3.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:anysphere:cursor:*:*:*:*:*:*:*:*
Версия от 1.1.7 (включая) до 1.3 (исключая)

EPSS

Процентиль: 11%
0.00037
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-78
NVD-CWE-noinfo

EPSS

Процентиль: 11%
0.00037
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-78
NVD-CWE-noinfo