CVE-2025-61591 | Cursor up to 1.7 MCP Service os command injection (GHSA-wj33-264c-j9cq)
A vulnerability categorized as critical has been discovered in Cursor up to 1.7. This affects an unknown part of the component MCP Service. The manipulation results in os command injection.
This vulnerability is reported as CVE-2025-61591. The attack can be launched remotely. No exploit exists.