CVE-2025-27554
CVSS 3.1 Score 9.9 of 10 (high)
Details
Published Mar 1, 2025
CWE ID 94
Summary
CVE-2025-27554 is a vulnerability affecting ToDesktop before version 2024-10-03, as used by Cursor before the same date and other applications. This vulnerability allows remote attackers to execute arbitrary commands on the build server. By exploiting a postinstall script in package.json, attackers can read sensitive information, such as secrets from the config.prod.json file, and deploy updates to any app. No instances of exploitation have been reported as of now.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.