By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Cyata flags agentic AI supply-chain risk in Cursor remote code execution bug – News
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Cyata flags agentic AI supply-chain risk in Cursor remote code execution bug – News
News

Cyata flags agentic AI supply-chain risk in Cursor remote code execution bug – News

News Room
Last updated: 2025/12/21 at 12:36 AM
News Room Published 21 December 2025
Share
Cyata flags agentic AI supply-chain risk in Cursor remote code execution bug –  News
SHARE

A new report out today from artificial intelligence security startup Cyata Security Ltd. details a critical remote code execution vulnerability in Cursor Inc.’s integrated development environment that exposed risks tied to trusted installation workflows and agentic AI tooling.

The vulnerability, tracked as CVE-2025-64106 and rated 8.8 in severity, affected Cursor’s Model Context Protocol installation flows and could have allowed attackers to execute arbitrary commands on a developer’s machine. Upon discovery, Cyata reported the vulnerability to Cursor and to the credit of both companies, it was patched within two days of discovery.

The issue arose due to Cursor using the growingly popular Model Context Protocol to connect AI assistants inside the IDE to external tools, databases and application programming interfaces, enabling more autonomous and agent-driven development workflows. The MCP connectivity introduced new attack surfaces, particularly where AI systems are granted system-level permissions during setup and configuration.

Cyata researchers discovered that Cursor’s MCP installation process could be manipulated to present users with a trusted installation dialog presented as Playwright, a popular automation tool, while executing malicious commands in the background. The user interface-based deception could have allowed attackers to trick users into inadvertently running harmful code under the guise of legitimate software.

The vulnerability stemmed from insufficient validation and trust enforcement within Cursor’s MCP deep-link handling. The process is designed to execute system-level commands when connecting external tools, but certain inputs could alter how those actions were represented to users, effectively masking unsafe behavior behind a legitimate-looking interface.

The issue did not rely on traditional exploit techniques such as memory corruption but instead abused logic and trust assumptions within the installation workflow itself. By leveraging a trusted execution path and recognizable tooling, attackers could reduce user suspicion and increase the likelihood of successful execution, highlighting how UI trust and workflow design have become critical security boundaries in agentic AI systems.

“As AI IDEs start wiring agents into real tools and real permissions, the installation flow becomes a security boundary, not a convenience,” said Shahar Tal, co-founder and chief executive officer at Cyata.”This issue shows how attackers can abuse trusted setup experiences to get code executed on a developer’s machine. Securing agentic workflows means treating UI trust, deep links and tool installation as part of your threat model.”

Cyata worked closely with Cursor to ensure a swift patch and continues to monitor emerging risks associated with agentic AI integration.

The venture capital-backed startup raised $8.5 million, its first disclosed funding round, in July. Investors in the company include TLV Partners Ltd. and a number of individual investors.

Image: News/Ideogram

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.

About News Media

News Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of News, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — News Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, News Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Iranian Infy APT Resurfaces with New Malware Activity After Years of Silence Iranian Infy APT Resurfaces with New Malware Activity After Years of Silence
Next Article Discover over 1,200 hidden Mac features with this  tool Discover over 1,200 hidden Mac features with this $28 tool
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

The industry notes the DoD’s lack of standardized software attestation processes
The industry notes the DoD’s lack of standardized software attestation processes
News
Full list of areas in the UK targeted in ‘dodgy’ Fire TV sticks crackdown
Full list of areas in the UK targeted in ‘dodgy’ Fire TV sticks crackdown
News
Blockbuster Deal: Take Over ,000 Off a 75-Inch Roku Pro Series Television
Blockbuster Deal: Take Over $1,000 Off a 75-Inch Roku Pro Series Television
News
Best Apple Deals of the Week: AirPods Pro 3 for 9, Plus Sitewide Sales at Samsung and Sonos
Best Apple Deals of the Week: AirPods Pro 3 for $199, Plus Sitewide Sales at Samsung and Sonos
News

You Might also Like

The industry notes the DoD’s lack of standardized software attestation processes
News

The industry notes the DoD’s lack of standardized software attestation processes

9 Min Read
Full list of areas in the UK targeted in ‘dodgy’ Fire TV sticks crackdown
News

Full list of areas in the UK targeted in ‘dodgy’ Fire TV sticks crackdown

10 Min Read
Blockbuster Deal: Take Over ,000 Off a 75-Inch Roku Pro Series Television
News

Blockbuster Deal: Take Over $1,000 Off a 75-Inch Roku Pro Series Television

5 Min Read
Best Apple Deals of the Week: AirPods Pro 3 for 9, Plus Sitewide Sales at Samsung and Sonos
News

Best Apple Deals of the Week: AirPods Pro 3 for $199, Plus Sitewide Sales at Samsung and Sonos

5 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?