CNNVD-202511-107 Information

CNNVD ID

CNNVD-202511-107

CVE-2025-64108

  • CNNVD Published: 2025-11-04

Description (Chinese)

Cursor是Cursor开源的一个 AI 代码编辑器。 Cursor 1.7.44及之前版本存在代码注入漏洞,该漏洞源于NTFS路径特性允许绕过敏感文件保护,可能导致远程代码执行。

Description (English)

Cursor is an AI code editor at Cursor Open Source. Cursor 1.7.44 and previous versions had a code injection loophole, which stemmed from NTFS path characteristics that allowed circumvention of sensitive file protection and could lead to remote code execution.

Hazard Level

Medium

Vulnerability Type

代码注入

Affected Vendor

Cursor

Published

2025-11-04

Last Modified

2026-02-24

References

https://github.com/cursor/cursor/security/advisories/GHSA-6r98-6qcw-rxrw https://access.redhat.com/security/cve/cve-2025-64108

Patch

https://cursor.com/cn

Share on: