CVE-2025-54131
Last modified
CVE-2025-54131 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Cursor is a code editor built for programming with AI. In versions below 1.3, an attacker can bypass the allow list in auto-run mode with a backtick (`) or $(cmd). EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
Cursor is a code editor built for programming with AI. In versions below 1.3, an attacker can bypass the allow list in auto-run mode with a backtick (`) or $(cmd). If a user has swapped Cursor from its default settings (requiring approval for every terminal call) to an allowlist, an attacker can execute arbitrary command execution outside of the allowlist without user approval. An attacker can trigger this vulnerability if chained with indirect prompt injection. This is fixed in version 1.3.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Anysphere | Cursor | < 1.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-54131?
How severe is CVE-2025-54131?
How do I fix CVE-2025-54131?
Are you affected by CVE-2025-54131?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
