Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-59944

Опубликовано: 03 окт. 2025
Источник: nvd
CVSS3: 8
CVSS3: 9.8
EPSS Низкий

Описание

Cursor is a code editor built for programming with AI. Versions 1.6.23 and below contain case-sensitive checks in the way Cursor IDE protects its sensitive files (e.g., */.cursor/mcp.json), which allows attackers to modify the content of these files through prompt injection and achieve remote code execution. A prompt injection can lead to full RCE through modifying sensitive files on case-insensitive fileystems. This issue is fixed in version 1.7.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:anysphere:cursor:*:*:*:*:*:*:*:*
Версия до 1.6.23 (включая)

EPSS

Процентиль: 49%
0.00258
Низкий

8 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-178

EPSS

Процентиль: 49%
0.00258
Низкий

8 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-178