logo

Cursor AI Extension Flaw Exposes Developer Tokens to Credential Theft

ID: 500b6150-ac5e-5607-9836-50d866f05b13

STIX ID: report--500b6150-ac5e-5607-9836-50d866f05b13

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Divya

...
...

LayerX disclosed a critical flaw called "CursorJacking" (CVSS 8.2) in the Cursor development environment where extensions can read a predictable, unencrypted local SQLite database to steal API keys and session tokens without special permissions; exploitation is low-effort and can lead to billing abuse, source-code/data exposure, and full account impersonation. Cursor was notified in February 2026 but had not released a patch by late April 2026; users should avoid untrusted extensions and the vendor should enforce secure system keychains and extension isolation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.