CNNVD-202511-362 Information

CNNVD ID

CNNVD-202511-362

CVE-2025-64109

  • CNNVD Published: 2025-11-05

Description (Chinese)

Cursor是Cursor开源的一个 AI 代码编辑器。 Cursor 2025.09.17-25b418f之前版本存在操作系统命令注入漏洞,该漏洞源于MCP服务器机制允许上传恶意MCP配置,可能导致远程代码执行。

Description (English)

Cursor is an AI code editor at Cursor Open Source. The previous version of Cursor 2025.09.17-25b418f contained a loophole in the operating system command, which originated from the MCP server mechanism allowing the uploading of malicious MCP configurations, which could lead to remote code execution.

Hazard Level

Medium

Vulnerability Type

操作系统命令注入

Affected Vendor

Cursor

Published

2025-11-05

Last Modified

2026-02-24

References

https://github.com/cursor/cursor/security/advisories/GHSA-4hwr-97q3-37w2 https://access.redhat.com/security/cve/cve-2025-64109

Patch

https://cursor.com/cn

Share on: