CVE-2025-54133: Anysphere Cursor

Critical severity, CVSS 9.6. EPSS: 0.4% chance of exploitation in the next 30 days.

Cursor is a code editor built for programming with AI. In versions 1.17 through 1.2, there is a UI information disclosure vulnerability in Cursor's MCP (Model Context Protocol) deeplink handler, allowing attackers to execute 2-click arbitrary system commands through social engineering attacks. When users click malicious `cursor://anysphere.cursor-deeplink/mcp/install` links, the installation dialog does not show the arguments being passed to the command being run. If a user clicks a malicious deeplink, then examines the installation dialog and clicks through, the full command including the arguments will be executed on the machine. This is fixed in version 1.3.

Affected products

  • Anysphere Cursor: from 1.1.7, before 1.3 (fixed in 1.3)

Published 2025-08-02. Last modified 2026-06-17.