CRITICAL
ToDesktop before 2024-10-03, as used by Cursor before 2024-10-03 and other applications, allows remote attackers to execute arbitrary commands on the build server (e.g., read secrets from the desktopify config.prod.json file), and consequently deploy updates to any app, via a postinstall script in package.json
Published Mar 1, 2025
9.9
CRITICALCVSS 3.1
EPSS 0.81%
Description
Affected products
Remediation
References (3)
Change history (0)
No recorded changes yet.