Cursor Arbitrary File Write Vulnerability in the Cursor Agent

Vulnerability

A vulnerability in the Cursor code editor, affecting versions 0.45.0 prior to 0.48.6, allows the Cursor Agent to automatically write to files outside the opened workspace. This issue arises from a regression in the application's file path modification permissions. Exploitation requires deliberate prompting, either by the user or through maliciously crafted context, making it highly impractical in real-world scenarios. Additionally, the edited file remains visible in the user interface for review, reducing the likelihood of unnoticed changes.

Impact

Exploitation of this vulnerability allows for arbitrary file writes outside the user's workspace, with the potential for overwriting important files or injecting malicious content into sensitive locations.

Remediation

The vulnerability has been patched in Cursor version 0.48.7. Users are advised to update to this version and to review the edits made by the Cursor Agent, especially when using context that may not be trusted.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.8
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.