Cursor Code Editor Remote Code Execution Vulnerability
Vulnerability
A remote code execution vulnerability exists in Cursor code editor versions through 1.7. This issue arises from the automatic loading of project-specific command-line interface (CLI) configurations from the current working directory, which could override certain global settings. Users running the CLI in a malicious repository could exploit this vulnerability by combining permissive configurations that allow shell commands with prompt injections delivered through project-specific rules or other mechanisms.
Impact
Exploitation of this vulnerability could lead to arbitrary code execution on the user's machine.
Remediation
Users can update to Cursor version 2025.09.17-25b418f to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
