logo

AI’s Open Secret: Why Your Cursor Extensions Can Silently Siphon Your API Keys

ID: a58050b4-18d6-5d6d-8942-7b0b633d4fab

STIX ID: report--a58050b4-18d6-5d6d-8942-7b0b633d4fab

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Ddos

...
...

LayerX researchers disclosed a high-severity (CVSS 8.2) vulnerability in the Cursor AI code editor: Cursor stores API keys and session tokens unencrypted in a local SQLite database (~/Library/Application Support/Cursor/User/globalStorage/state.vscdb), and any installed extension can read and exfiltrate those secrets silently. The proof-of-concept shows malicious extensions can locate the DB, query for secrets, and send them to an attacker-controlled server with no user interaction; Cursor acknowledged the finding but treated it as within the user's trust boundary and had not fixed it as of April 28, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.