Hackers Use Rogue MCP Server to Inject Malicious Code and Take Over Cursor’s Browser
ID: 54ee769c-1676-5554-9798-faca793d7eeb
STIX ID: report--54ee769c-1676-5554-9798-faca793d7eeb
Feed Name: Cyber Press
Security researchers disclosed a critical vulnerability in the Cursor AI code editor that lets malicious Model Context Protocol (MCP) servers register locally and inject arbitrary JavaScript into Cursor's embedded browser. The injected code can overwrite page content, replace legitimate login pages with phishing interfaces to harvest credentials, persist across tabs, and enable further actions such as privilege escalation and system modification; a proof-of-concept is provided and mitigations include vetting MCP servers/extensions, disabling auto-run, and deploying enterprise detection and reputation controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
