MCPoison Attack Abuses Cursor IDE to Run Arbitrary System Commands

Post Reply
Shane1145
Posts: 1624
Joined: Wed Sep 25, 2024 2:31 pm

MCPoison Attack Abuses Cursor IDE to Run Arbitrary System Commands

Post by Shane1145 »

Cybersecurity researchers have uncovered a critical vulnerability in Cursor IDE that allows attackers to execute arbitrary system commands through a sophisticated trust bypass mechanism, potentially compromising developer workstations across collaborative coding environments.

Check Point Research disclosed the vulnerability, designated CVE-2025-54136 and dubbed “MCPoison,” which exploits Cursor IDE’s Model Context Protocol (MCP) trust system to achieve persistent remote code execution.


https://gbhackers.com/mcpoison-attack-a ... ursor-ide/
Post Reply