Cursor AI code editor Remote Code Execution Vulnerability
Amazon Q Vulnerability: Compromise via MCP Auto-Execution wiz.io
STABLE
What Happened
Amazon Q Vulnerability: Compromise via MCP Auto-Execution wiz.io
Why This Matters
The evidence matters to defenders using Cursor AI code editor because it could let an attacker run code in affected environments.
Recommended Action
Confirm whether may is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.
Exposure
Exposure unknown
Jun 26, 2026 12:30
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: UNKNOWN
Primary entities:
Authoritative Intelligence
Public GitHub References
Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal โ it does not fetch or display exploit code.
CVE-2025-54136: 3 public repository references found.
Security advisory / research reference
Free security-baseline rule for Claude Code, Codex, and Cursor: treats MCP tool descriptions as untrusted input (OWASP MCP Top 10 MCP03, CVE-2025-54136).
0 stars
Open repositoryPublic GitHub reference
A lightweight mcp to prevent poisoning CVE (CVE-2025-54136), researchers hijacking Claude Code/Copilot/Gemini via prompt injection, and hundreds of MCP servers exposed with zero auth, this mcp protects the individual developer's laptop, where most MCP servers actually run.
0 stars ยท TypeScript
Open repositoryA public PoC or exploit-related repository means weaponization material may exist in the open. It does not prove your environment was targeted.
Timeline
-
Incident first seen
Aug 05, 2025 05:30BugSkan first recorded this incident.
-
Cursor AI Code Editor Vulnerability Enables RCE via Malicious MCP File Swaps Post Approval - The Hacker News
Aug 05, 2025 05:30thehackernews.com ยท Vulnerability
-
Amazon Q Vulnerability: Compromise via MCP Auto-Execution - wiz.io
Jun 26, 2026 12:30news.google.com ยท Vulnerability
-
Latest observed development
Jun 26, 2026 12:30Most recent source or update associated with this incident.
Sources
thehackernews.com ยท Aug 05, 2025 05:30
CVE-2025-54136, codenamed MCPoison, is a high-severity vulnerability in the Cursor AI code editor that allows for remote code execution (RCE). It exploits how the editor handles Model Context Protocol (MCP) configurations, permitting an attacker to silently swap a previously approved, benign configuration with a malicious payload without re-prompting the user.
Open publisher sourcenews.google.com ยท Jun 26, 2026 12:30
Amazon Q Vulnerability: Compromise via MCP Auto-Execution wiz.io
Open publisher sourceRelated Incidents
Other BugSkan incidents that share identifiers, products, or vendors with this report.
My Interests Match
Create an account to see which incidents overlap with your interests.