
Security
What is the Cursor vulnerability "MCPosion"? The Threat of RCE Attacks Targeting AI Editors
Explains the vulnerability MCPosion (CVE-2025-54136) discovered in the AI code editor "Cursor". We have identified flaws in the trust model and summarized the methods and countermeasures that can lead to remote code execution (RCE) by exploiting MCP settings. We are now publishing methods to protect ourselves from new threats lurking in AI-assisted development environments. |Colorkrew Security