cursor-ai-code-editor-vulnerability-enables-rce-via-malicious-mcp-file-swaps-post-approval

Cybersecurity analysts have revealed a critical security vulnerability in the AI-driven code editor Cursor that may lead to remote code execution.
The flaw, listed as CVE-2025-54136 (CVSS score: 7.2), has been dubbed MCPoison by Check Point Research, due to its exploitation of an anomaly in how the application manages changes to the Model.


Leave a Reply

Your email address will not be published. Required fields are marked *

Share This