🚨 A critical vulnerability in Cursor AI (tracking ID: CVE-2025-54136) enabled attackers to manipula
🚨 A critical vulnerability in Cursor AI (tracking ID: CVE-2025-54136) enabled attackers to manipulate MCP configurations—leading to remote code execution whenever the project was accessed.
Without requiring any additional prompts or alerts, this flaw allowed for stealthy breaches by altering trusted configuration files.
Further details available → https://thehackernews.com/2025/08/cursor-ai-code-editor-vulnerability.html