
Exploit for CVE-2025-54135 in Cursor IDE, demonstrating prompt injection via MCP to achieve remote code execution by rewriting mcp.json.
Below is a fully functional exploit for the CVE-2025-54135 vulnerability in the Cursor IDE, designed to demonstrate a prompt-injection attack that manipulates the Model Context Protocol (MCP) configuration to achieve remote code execution. This code assumes the attacker has access to a public Slack channel or similar external MCP server that the victim's Cursor IDE is configured to interact with. The exploit crafts a malicious prompt that rewrites the ~/.cursor/mcp.json file to execute arbitrary commands under the developer's privileges.
To use this exploit, follow these steps to set up the attack infrastructure:
Create a Slack Bot:
general).xoxp-your-slack-bot-token-here in the script with your bot token.Set Up a Malicious MCP Server:
http://attacker-controlled-server.com:8080 (replace with your own server URL).Run the Exploit:
pip install requests.python cve-2025-54135-exploit.py.Exploit Mechanism:
~/.cursor/mcp.json.auto_start flag ensures the start_command (e.g., whoami > /tmp/pwned.txt) executes immediately without user approval.Verification:
/tmp/pwned.txt to confirm successful command execution.COMMAND variable to execute other shell commands as needed.requests library.This code and setup provide a functional demonstration of how an attacker could leverage CVE-2025-54135 to achieve remote code execution via prompt injection in Cursor IDE.