
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64108 is a path traversal and sensitive file modification vulnerability in Cursor, an AI-powered code editor developed by Anysphere. NTFS path quirks (short path and data stream syntax) allow a prompt injection attacker to bypass Cursor's sensitive file protection mechanisms and overwrite files that normally require human approval. The vulnerability affects Cursor versions 1.7.44 and below and is limited to systems running NTFS file systems (i.e., Windows). It was published on November 4, 2025, and carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Red Hat CVE).
The root cause is improper limitation of a pathname to a restricted directory (CWE-22 / Path Traversal) combined with improper control of code generation (CWE-94 / Code Injection). Cursor implements guardrails requiring human approval before overwriting certain sensitive files; however, NTFS-specific path representations — such as 8.3 short path names and alternate data stream syntax — are not normalized before these guardrails are evaluated, allowing an attacker to reference a protected file via an alternate path form that bypasses the protection check. Exploitation must be chained with a prompt injection attack or a malicious AI model interaction that causes Cursor's AI agent to issue file-write operations using the crafted NTFS paths. The fix normalizes NTFS paths before applying guardrails (GitHub Advisory).
Successful exploitation allows an attacker to overwrite sensitive files within the Cursor application environment without triggering the required human approval prompt, bypassing an intended security control. Modification of certain protected files can lead to remote code execution (RCE), with high confidentiality, integrity, and availability impact on the affected system. The attack requires only low privileges and no user interaction beyond the initial prompt injection or malicious model attachment, making the potential blast radius significant for Windows-based developer workstations running Cursor (GitHub Advisory, Red Hat CVE).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Red Hat CVE). The EPSS score is approximately 0.049%, reflecting a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires chaining with a prompt injection or malicious AI model interaction, which adds complexity but is a realistic threat vector given the growing use of AI-assisted coding tools (GitHub Advisory).
PROGRA~1\...) or an alternate data stream path — that bypasses Cursor's sensitive path detection logic.~1, ~2, or :stream syntax in write operations.The vendor has released a fix in Cursor version 2.0, which normalizes NTFS paths before applying sensitive file guardrails. All users on version 1.7.44 or below should upgrade to version 2.0 immediately. As interim mitigations, restrict network access to the Cursor application, apply the principle of least privilege to the user account running Cursor, implement strict monitoring for unexpected file modifications in Cursor's directories, and exercise caution with untrusted AI model sources or external prompts (GitHub Advisory, Red Hat CVE).
The vulnerability was credited to researcher Philts and disclosed via GitHub Security Advisories by Cursor maintainer hmwildermuth on November 3, 2025. Red Hat tracked the CVE as part of their standard advisory process. Community discussion has been limited, with no major media coverage or notable researcher commentary beyond the initial advisory (GitHub Advisory, Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."