Back to Database
Status published
Critical
CVE-2025-62354
Improper neutralization of special elements used in an OS command...
Vulnerability Description
Improper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized attacker to execute commands that are outside of those specified in the allowlist, resulting in arbitrary code execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-62354
Credits & Attribution
No credits recorded in the NVD database.
More from cursor
View All →CVE-2025-64110
Cursor: Authentication Bypass Possible via New Cursorignore Write
High
8.7
CVE-2025-64109
Cursor CLI Beta: Command Injection via Untrusted MCP Configuration
High
8.8
CVE-2025-64108
Cursor's Sensitive File Modification can Lead to NTFS Path Quirks
High
8.8
CVE-2025-64107
Cursor is Vulnerable to Path Manipulation Using Backslashes on Windows
High
8.8
CVE-2025-64106
Cursor: Speedbump Modal Bypass in MCP Server Deep-Link
High
8.8
Affected Vendor
cursor
View all reports →Affected Software
cursor
Vulnerable Versions:
1.3.4
Timeline
Official Publish:
November 26th, 2025
Last Modified:
November 26th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H