CVE Explorer
CVE-2025-64107
Cursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may lead to RCE. Cursor detects path manipulation via forward slashes (./.cursor/./././././mcp.json etc.), and requires human approval to complete the operation. However, the same kind of manipulation using backslashes was not correctly detected, allowing an attacker who had already achieved prompt injection or some other level of control to overwrite sensitive editor files without
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"cursor","vendor":"cursor","versions":[{"status":"affected","version":"< 2.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:1dafd3fd6488c7f4d40047c8e46c0d73fb3551bc422b79bdaa50922764d2f375 · sha256:b2f2e7eaf6c3632c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:1dafd3fd6488c7f4d40047c8e46c0d73fb3551bc422b79bdaa50922764d2f375 · sha256:b2f2e7eaf6c3632c… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1dafd3fd6488c7f4d40047c8e46c0d73fb3551bc422b79bdaa50922764d2f375 · sha256:b2f2e7eaf6c3632c… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/cursor/cursor/security/advisories/GHSA-2jr2-8wf5-v6pf","tags":["x_refsource_CONFIRM"],"url":"https://github.com/cursor/cursor/security/advisories/GHSA-2jr2-8wf5-v6pf"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1dafd3fd6488c7f4d40047c8e46c0d73fb3551bc422b79bdaa50922764d2f375 · sha256:b2f2e7eaf6c3632c… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.