Severity
Exposure
Date of incident
Cursor MCP Trust Bypass
confirmed
Tier -
A
Approved MCP config changed silently — no re-approval hop on tool definition drift.
What Happened
Researcher contributed benign MCP config to shared repo; after one approval, attacker swapped command/args to malicious payload. Cursor executed without second prompt until v1.3 fix.
Sumarry
CVE-2025-54136 (MCPoison): Cursor bound MCP trust to config name only — silent modification of approved MCP servers achieved persistent code execution without re-approval.
Detect
MCP config digest diff + mandatory re-approval on any change
What Happened
MCP proxy with pinned schemas; PR review on .cursor/mcp.json
Blekline //
MCP proxy schema pin + evaluate_tool_call on config change
Without agent boundary //
IDE trusts prior approval — attacker swaps command after one click
