Cursor AI Extension Flaw Exposes Developer Tokens to Credential Theft
ID: 500b6150-ac5e-5607-9836-50d866f05b13
STIX ID: report--500b6150-ac5e-5607-9836-50d866f05b13
Feed Name: GBHackers
LayerX disclosed a critical flaw called "CursorJacking" (CVSS 8.2) in the Cursor development environment where extensions can read a predictable, unencrypted local SQLite database to steal API keys and session tokens without special permissions; exploitation is low-effort and can lead to billing abuse, source-code/data exposure, and full account impersonation. Cursor was notified in February 2026 but had not released a patch by late April 2026; users should avoid untrusted extensions and the vendor should enforce secure system keychains and extension isolation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
