CVE-2025-61590 | Cursor up to 1.6 Visual Studio Code Workspace vscode/settings.json code injection (GHSA-xg6w-rmh5-r77r)
A vulnerability, which was classified as critical, was found in Cursor up to 1.6. The impacted element is an unknown function of the file vscode/settings.json of the component Visual Studio Code Workspace Handler. The manipulation results in code injection.
This vulnerability is identified as CVE-2025-61590. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.