CVE-2025-32018
CVSS 3.1 Score 8 of 10 (high)
Details
Published Apr 8, 2025
CWE ID 22
Summary
CVE-2025-32018 is a vulnerability affecting the Cursor code editor, specifically versions 0.45.0 through 0.48.6. During this period, the Cursor Agent was given expanded permissions to modify files automatically. Under certain conditions, the agent could be manipulated to edit files outside of the opened workspace. Though successful exploitation required deliberate prompting, the edited files remained visible to users for review, increasing the likelihood of detection. This issue has been resolved in version 0.48.7.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Iveco Cursor
Affected Vendors
- Iveco Group