CNNVD-202511-362 Information
Nov 05, 2025
cve
CNNVD ID
CNNVD-202511-362
Related CVE
- CNNVD Published: 2025-11-05
Description (Chinese)
Cursor是Cursor开源的一个 AI 代码编辑器。 Cursor 2025.09.17-25b418f之前版本存在操作系统命令注入漏洞,该漏洞源于MCP服务器机制允许上传恶意MCP配置,可能导致远程代码执行。
Description (English)
Cursor is an AI code editor at Cursor Open Source. The previous version of Cursor 2025.09.17-25b418f contained a loophole in the operating system command, which originated from the MCP server mechanism allowing the uploading of malicious MCP configurations, which could lead to remote code execution.
Hazard Level
Medium
Vulnerability Type
操作系统命令注入
Affected Vendor
Cursor
Published
2025-11-05
Last Modified
2026-02-24
References
https://github.com/cursor/cursor/security/advisories/GHSA-4hwr-97q3-37w2 https://access.redhat.com/security/cve/cve-2025-64109