CVE-2025-54136 Remote Code Execution Vulnerability affecting AI
Evidence indicates that the affected technology is affected by remote code execution.
What Happened
Evidence indicates that the affected technology is affected by remote code execution.
Why This Matters
The evidence matters to defenders using Cursor AI Code because it could let an attacker run code in affected environments.
Recommended Action
No confirmed vendor remediation is available in the current evidence. Confirm whether Cursor AI Code is present in your environment and review the affected configuration.
Exposure
Aug 05, 2025 05:30
Aug 05, 2025 05:30
Exploitation status: UNKNOWN
Primary entities:
Authoritative Intelligence
Timeline
-
Incident first seen
Aug 05, 2025 05:30BugSkan first recorded this incident.
-
Cursor AI Code Editor Vulnerability Enables RCE via Malicious MCP File Swaps Post Approval - The Hacker News
Aug 05, 2025 05:30thehackernews.com · Vulnerability
Sources
thehackernews.com · Aug 05, 2025 05:30
CVE-2025-54136, codenamed MCPoison, is a high-severity vulnerability in the Cursor AI code editor that allows for remote code execution (RCE). It exploits how the editor handles Model Context Protocol (MCP) configurations, permitting an attacker to silently swap a previously approved, benign configuration with a malicious payload without re-prompting the user.
Open publisher sourceWatchlist Match
Create an account to see which incidents overlap with the technologies you monitor.