Anysphere

Cursor

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 04.11.2025 23:24:46
  • Zuletzt bearbeitet 07.11.2025 13:04:09

Cursor is a code editor built for programming with AI. In versions 1.7.23 and below, a logic bug allows a malicious agent to read sensitive files that should be protected via cursorignore. An attacker who has already achieved prompt injection, or a m...

  • EPSS 0.07%
  • Veröffentlicht 04.11.2025 22:58:53
  • Zuletzt bearbeitet 10.11.2025 18:38:51

Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a prompt injection attacker to circumvent sensitive file protections and overwrite files which Cursor requires human approval to overw...

  • EPSS 0.04%
  • Veröffentlicht 04.11.2025 22:51:42
  • Zuletzt bearbeitet 10.11.2025 19:54:02

Cursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may lead to RCE. Cursor detects path manipulation via forward slashes (./.cursor/./././././mcp.json etc.), and requires human approval...

  • EPSS 0.06%
  • Veröffentlicht 04.11.2025 22:48:14
  • Zuletzt bearbeitet 07.11.2025 17:48:28

Cursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor's MCP server installation enables specially crafted deep-links to bypass the standard security warnings and conceal executed comma...

  • EPSS 0.18%
  • Veröffentlicht 03.10.2025 20:15:30
  • Zuletzt bearbeitet 16.10.2025 18:16:19

Cursor is a code editor built for programming with AI. Versions 1.6.23 and below contain case-sensitive checks in the way Cursor IDE protects its sensitive files (e.g., */.cursor/mcp.json), which allows attackers to modify the content of these files ...

  • EPSS 0.19%
  • Veröffentlicht 03.10.2025 17:28:03
  • Zuletzt bearbeitet 09.10.2025 17:30:22

Cursor is a code editor built for programming with AI. In versions 1.7 and below, a vulnerability in the way Cursor CLI Agent protects its sensitive files (i.e. */.cursor/cli.json) allows attackers to modify the content of the files through prompt in...

  • EPSS 0.2%
  • Veröffentlicht 03.10.2025 17:23:37
  • Zuletzt bearbeitet 09.10.2025 17:23:11

Cursor is a code editor built for programming with AI. In versions 1.7 and below, automatic loading of project-specific CLI configuration from the current working directory (<project>/.cursor/cli.json) could override certain global configurations in ...

  • EPSS 0.19%
  • Veröffentlicht 03.10.2025 16:44:54
  • Zuletzt bearbeitet 17.10.2025 17:25:27

Cursor is a code editor built for programming with AI. In versions 1.7 and below, when MCP uses OAuth authentication with an untrusted MCP server, an attacker can impersonate a malicious MCP server and return crafted, maliciously injected commands du...

  • EPSS 0.19%
  • Veröffentlicht 03.10.2025 16:27:34
  • Zuletzt bearbeitet 17.10.2025 17:24:46

Cursor is a code editor built for programming with AI. Versions 1.6 and below are vulnerable to Remote Code Execution (RCE) attacks through Visual Studio Code Workspaces. Workspaces allow users to open more than a single folder and save specific sett...

  • EPSS 0.07%
  • Veröffentlicht 03.10.2025 06:48:30
  • Zuletzt bearbeitet 20.10.2025 18:41:07

Cursor is a code editor built for programming with AI. In versions 1.6 and below, Mermaid (a to render diagrams) allows embedding images which then get rendered by Cursor in the chat box. An attacker can use this to exfiltrate sensitive information t...