AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2025-54132.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 4.4No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSMicrosoft vendor recordModified Oct 14, 2025

Disclosure summary

Cursor is a code editor built for programming with AI. In versions below 1.3, Mermaid (which is used to render diagrams) allows embedding images which then get rendered by Cursor in the chat box. An attacker can use this to exfiltrate sensitive information to a third-party attacker controlled server through an image fetch after successfully performing a prompt injection. A malicious model (or hallucination/backdoor) might also trigger this exploit at will. This issue requires prompt injection from malicious data (web, image upload, source code) to be exploited. In that case, it can send sensitive information to an attacker-controlled external server. GitHub created this CVE on their behalf. The documented Visual Studio updates incorporate updates in Mermaid which address this vulnerability. Please see Security Update Guide Supports CVEs Assigned by Industry Partners for more information.

Source-reported weakness categories

CWE-77

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

Microsoft Security Updates (CVRF) · 2025-Oct

Open original source · Updated Oct 14, 2025

GitHub CVE-2025-54132: Arbitrary Image Fetch in Mermaid Diagram Tool

Maximum of vendor-reported product scores; products and fixed builds are associations, not a universal affected-version statement.

Microsoft maximum product score: 4.4

VendorProduct / associationVersion / bounds
Microsoft update guideMicrosoft Visual Studio 2022 version 17.14 (MSRC status code 3)

Vendor remediation references

  • Release Notes · build 17.14.17 · product IDs 16767
  • Vendor guidance · product IDs 16767
Embrace The Red · RSS-357aaed9fc8209e2fd36ceb379691972f83

Open original source · Updated Aug 04, 2025

Cursor IDE: Arbitrary Data Exfiltration Via Mermaid (CVE-2025-54132)

CVE mention in publisher metadata; check the original affected versions.

Original records & references

PUBLISHED 2025-10-14T03:00:00-04:00
MODIFIED 2025-10-14T03:00:00-04:00
INGESTED 2026-10-08T12:45:30-04:00