4 Sources
[1]
Vibe coding tool Cursor allows persistent code execution
Check Point researchers uncovered a remote code execution bug in popular vibe-coding AI tool Cursor that could allow an attacker to poison developer environments by secretly modifying a previously approved Model Context Protocol (MCP) configuration, silently swapping it for a malicious command
[2]
Cursor AI Code Editor Vulnerability Enables RCE via Malicious MCP File Swaps Post Approval
Cybersecurity researchers have disclosed a high-severity security flaw in the artificial intelligence (AI)-powered code editor Cursor that could result in remote code execution. The vulnerability, tracked as CVE-2025-54136 (CVSS score: 7.2), has been codenamed MCPoison by Check Point Research,
[3]
AI-powered Cursor IDE vulnerable to prompt-injection attacks
A vulnerability that researchers call CurXecute is present in almost all versions of the AI-powered code editor Cursor, and can be exploited to execute remote code with developer privileges. The security issue is now identified as CVE-2025-54135 and can be leveraged by feeding the AI agent a
[4]
Cursor AI Code Editor Fixed Flaw Allowing Attackers to Run Commands via Prompt Injection
Cybersecurity researchers have disclosed a now-patched, high-severity security flaw in Cursor, a popular artificial intelligence (AI) code editor, that could result in remote code execution. The vulnerability, tracked as CVE-2025-54135 (CVSS score: 8.6), has been addressed in version 1.3 released
Share
Copy Link
Multiple security flaws discovered in the AI-powered code editor Cursor, including a high-severity vulnerability that could lead to remote code execution, highlighting potential risks in AI-assisted development tools.
Cybersecurity researchers have uncovered a series of high-severity vulnerabilities in Cursor, a popular AI-powered code editor. The most critical flaw, dubbed "MCPoison" (CVE-2025-54136), could allow attackers to achieve remote code execution by exploiting the way Cursor handles Model Context Protocol (MCP) server configurations
1
.
Source: The Register
The MCPoison vulnerability stems from Cursor's one-time approval process for MCP configurations. Once an initial configuration is approved, Cursor trusts all future modifications without requiring new validation. This trust model can be exploited by attackers to silently swap a benign MCP command with a malicious payload, potentially gaining persistent access to a victim's machine
2
.
Source: Hacker News
Researchers also identified another vulnerability called "CurXecute" (CVE-2025-54135), which allows attackers to execute remote code with developer privileges by feeding the AI agent a malicious prompt. This flaw could potentially lead to ransomware attacks, data theft, and AI manipulation
3
.Attackers could exploit these vulnerabilities through various methods:

Source: BleepingComputer
These vulnerabilities highlight the potential risks associated with AI-powered development tools. As AI agents bridge external, internal, and interactive worlds, security models must account for how external context can affect agent runtime
4
.Related Stories
Cursor has addressed these vulnerabilities in version 1.3, released on July 29, 2025. Key improvements include:
The discovery of these vulnerabilities has raised concerns about the security of AI-assisted coding tools. Check Point Research warns that this is just the first in a series of flaws they've uncovered in developer-focused AI platforms, suggesting that more security issues may come to light in the near future
1
.As AI continues to shape modern software workflows, cybersecurity researchers emphasize the need for robust security measures and thorough vetting of AI-powered development tools to mitigate potential risks and protect sensitive data and intellectual property.
Summarized by
Navi
[1]
[2]
[3]
12 Sept 2025•Technology

07 Dec 2025•Technology

17 Apr 2026•Technology

1
Science and Research

2
Policy and Regulation

3
Technology