Skip to main content
Loading…
    CVE-2025-54131 — Cursor is a code editor built for programming with AI. In versions below 1.3, an attacker can bypass the allow list in auto-run mode with a backtick (`) or $(cmd). If a user has swapped Cursor from it — CVE Database · The Intelligence Room