A critical vulnerability in Cursor, the rapidly growing AI-powered code editor, that enables persistent remote code execution through manipulation of the Model Context Protocol (MCP) validation system.
The vulnerability, tracked as CVE-2025-54136 and dubbed "MCPoison," exploits a trust bypass mechanism that allows attackers to...
A critical security vulnerability in the popular AI-powered code editor Cursor IDE has been disclosed that allows attackers to execute remote code without any user interaction.
The flaw, dubbed "CurXecute" and tracked as CVE-2025-54135, received a severity rating of 8.6 and has been patched...