Check Point Research reveals a persistent RCE flaw in Cursor IDE, allowing silent code execution via trusted plugins.
Curated from blog.checkpoint.com →
Cursor asks before it will run a Model Context Protocol server, which is how an AI editor reaches tools and data. Check Point found in July 2025 that the approval attached to the fact of the server rather than to what it does: once a teammate had accepted a harmless entry, anyone who could commit to the repository could rewrite that entry to run any command, and it would run silently on every colleague's machine from then on. Disclosed 16 July, fixed in Cursor 1.3 on 29 July by re-prompting on any change to the configuration, down to an added space. It sits alongside a second Cursor flaw disclosed the same week and is the cleanest example of the new class of problem here: consent given once to an agent's tool, and the tool changing underneath it.