CVE-2025-54136

HIGH

Cursor < 1.3 - Remote Code Execution via MCP Configuration File Tampering

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2025-54136. PoCs published by adminlove520, Sushank05, PRE5T0.

AI-analyzed exploit summary The repository contains functional exploit code for multiple CVEs, including authentication bypass vulnerabilities in TOTOLINK devices and a scanner for Fortinet SSL VPN (CVE-2024-21762). The PoCs demonstrate the vulnerabilities with clear technical details and functional code.

Description

Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and persistent code execution by modifying an already trusted MCP configuration file inside a shared GitHub repository or editing the file locally on the target's machine. Once a collaborator accepts a harmless MCP, the attacker can silently swap it for a malicious command (e.g., calc.exe) without triggering any warning or re-prompt. If an attacker has write permissions on a user's active branches of a source repository that contains existing MCP servers the user has previously approved, or allows an attacker has arbitrary file-write locally, the attacker can achieve arbitrary code execution. This is fixed in version 1.3.

Exploits (3)

github WORKING POC 2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-54136

The repository contains functional exploit code for multiple CVEs, including authentication bypass vulnerabilities in TOTOLINK devices and a scanner for Fortinet SSL VPN (CVE-2024-21762). The PoCs demonstrate the vulnerabilities with clear technical details and functional code.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: TOTOLINK LR350, TOTOLINK T6, Fortinet SSL VPN
No auth needed
Prerequisites: network access to the target device
mistral-large-3 · analyzed Feb 27, 2026 Full analysis →
nomisec WORKING POC
by Sushank05 · poc
https://github.com/Sushank05/mcp-doorman

This repository provides a security gateway (mcp-doorman) for the Model Context Protocol (MCP) servers, implementing protective measures against tool poisoning, rug-pull attacks, injection patterns, and policy enforcement. The code is a functional PoC that acts as a proxy to filter and audit tool calls between clients and upstream MCP servers.

Classification
Working Poc 98%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Model Context Protocol (MCP) servers (e.g., @modelcontextprotocol/sdk)
No auth needed
Prerequisites: Access to an MCP server (either local or remote) · Configuration file setup for upstream servers · Node.js environment to run the gateway
mistral-large-3 · analyzed Jul 08, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.2607
EPSS Percentile 97.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
anysphere/cursor < 1.3
Published Aug 02, 2025
Tracked Since Feb 18, 2026