logo

Hackers Use Rogue MCP Server to Inject Malicious Code and Take Over Cursor’s Browser

ID: 54ee769c-1676-5554-9798-faca793d7eeb

STIX ID: report--54ee769c-1676-5554-9798-faca793d7eeb

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2025-11-14

Date Updated: 2026-04-19

Author: AnuPriya

...
...

Security researchers disclosed a critical vulnerability in the Cursor AI code editor that lets malicious Model Context Protocol (MCP) servers register locally and inject arbitrary JavaScript into Cursor's embedded browser. The injected code can overwrite page content, replace legitimate login pages with phishing interfaces to harvest credentials, persist across tabs, and enable further actions such as privilege escalation and system modification; a proof-of-concept is provided and mitigations include vetting MCP servers/extensions, disabling auto-run, and deploying enterprise detection and reputation controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.