Cursor AI Extension Token Access Flaw Could Lead to Full Credential Compromise
ID: 7fcd3ed1-78e1-547b-9a00-bc9e2a8b47a2
STIX ID: report--7fcd3ed1-78e1-547b-9a00-bc9e2a8b47a2
Feed Name: Cyber Press
Security researchers disclosed a CVSS 8.2 vulnerability in the Cursor development environment that allows any installed extension to query a predictable, unencrypted local SQLite database and exfiltrate plaintext API keys and session tokens. The flaw—caused by insecure credential storage and no isolation/sandboxing for extensions—enables stealthy credential theft with high potential impact (cloud and API abuse); Cursor had not released a patch as of April 2026 and users are advised to avoid untrusted extensions, rotate keys, and use external secure storage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
