Skip to content

CVE-2025-64109

CVE

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
August 11, 2026
Last Seen
August 12, 2026
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A security flaw in Cursor's CLI agent enables cloned repositories to execute arbitrary commands on a developer's machine before trust verification. This vulnerability affects users who start the agent with the worktree flag, allowing commands to run without user consent or sandbox restrictions. The...

Public Exploits

Checking GitHub for proof-of-concept code…