logo

Developer Alert: “CursorJack” Technique Weaponizes Deeplinks to Hijack Cursor IDE

ID: eca685af-66b6-55a9-beff-ea0bedc5252f

STIX ID: report--eca685af-66b6-55a9-beff-ea0bedc5252f

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-03-20

Date Updated: 2026-04-23

Author: Ddos

...
...

Proofpoint Threat Research disclosed 'CursorJack', a vulnerability in the Cursor AI code editor where manipulated cursor:// MCP deeplinks can be socially engineered to execute arbitrary OS commands or install malicious MCP servers on a developer's workstation; a single click plus consent may enable persistent compromise, exposing credentials, source code, and supply-chain risks, and Proof-of-Concept code has been published.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.