Severity

critical

Exposure

5/5

Date of incident

August 1, 2025
Cursor MCP Trust Bypass

confirmed

Tier -

A

Approved MCP config changed silently — no re-approval hop on tool definition drift.
What Happened

Researcher contributed benign MCP config to shared repo; after one approval, attacker swapped command/args to malicious payload. Cursor executed without second prompt until v1.3 fix.

Sumarry

CVE-2025-54136 (MCPoison): Cursor bound MCP trust to config name only — silent modification of approved MCP servers achieved persistent code execution without re-approval.

Detect

MCP config digest diff + mandatory re-approval on any change

What Happened

MCP proxy with pinned schemas; PR review on .cursor/mcp.json

Blekline //

MCP proxy schema pin + evaluate_tool_call on config change

Without agent boundary //

IDE trusts prior approval — attacker swaps command after one click

Financial services AI security use case

Looking to integrate AI company-wide?