Cursor AI Code Editor Vulnerability Enables RCE via Malicious MCP File Swaps Post Approval

Cybersecurity researchers have disclosed a high-severity security flaw in the artificial intelligence (AI)-powered code editor Cursor that could result in remote code execution.
The vulnerability, tracked as CVE-2025-54136 (CVSS score: 7.2), has been codenamed MCPoison by Check Point Research, owing to the fact that it exploits a quirk in the way the software handles modifications to Model

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

Misconfigurations Are Not Vulnerabilities: The Costly Confusion Behind Security Risks

Next Post

Google’s August Patch Fixes Two Qualcomm Vulnerabilities Exploited in the Wild

Related Posts
Total
0
Share