← Vulnerability feed

Vulnerability record · CVE-2025-64106 · published 4 November 2025

CVE-2025-64106: Anysphere cursor os command injection vulnerability

Anysphere · Cursor

Cursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor's MCP server installation enables specially crafted deep-links to bypass the standard security warnings and conceal executed commands from users if they choose to accept the server. If an attacker is able to convince a victim to navigate to a malicious deeplink, the victim will not see the correct speedbump modal, and if they choose to accept, will execute commands specified by the attackers deeplink.

8.8 CVSS 3.1 High EPSS 0.37% · top 71.9% CWE-78 · OS command injection
8.8CVSS 3.1 base score
0.37%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Cursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor's MCP server installation enables specially crafted deep-links to bypass the standard security warnings and conceal executed commands from users if they choose to accept the server. If an attacker is able to convince a victim to navigate to a malicious deeplink, the victim will not see the correct speedbump modal, and if they choose to accept, will execute commands specified by the attackers deeplink.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-64106 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-26268Anysphere cursor missing authorization vulnerabilityCursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicio…EPSS 0.42%9.8CVE-2025-59944Anysphere cursor vulnerabilityCursor is a code editor built for programming with AI. Versions 1.6.23 and below contain case-sensitive checks in the way Cursor IDE protects its sen…EPSS 0.41%9.8CVE-2025-54130Anysphere cursor improper authorization vulnerabilityCursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions less than 1.3.9. If…EPSS 0.30%9.8CVE-2025-54135Anysphere cursor os command injection vulnerabilityCursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions below 1.3.9, If the…EPSS 1.8%9.3CVE-2026-50548Anysphere cursor path traversal vulnerabilityCursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox gra…EPSS 1.0%9.3CVE-2026-50549Anysphere cursor link following vulnerabilityCursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, the…EPSS 1.0%8.8CVE-2025-64107Anysphere cursor path traversal vulnerabilityCursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may lead to RCE. Cursor detects p…EPSS 0.36%8.8CVE-2025-64108Anysphere cursor path traversal vulnerabilityCursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a prompt injection attacker to ci…EPSS 0.45%

Source: NIST National Vulnerability Database (record CVE-2025-64106), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.