ToDesktop before 2024-10-03, as used by Cursor before...
Critical severity
Unreviewed
Published
Mar 1, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Mar 1, 2025
Published to the GitHub Advisory Database
Mar 1, 2025
ToDesktop before 2024-10-03, as used by Cursor before 2024-10-03 and other applications, allows remote attackers to execute arbitrary commands on the build server (e.g., read secrets from the desktopify config.prod.json file), and consequently deploy updates to any app, via a postinstall script in package.json. No exploitation occurred.
References