2-Click Cursor Exploit Enables Dev Environment Takeover
ID: 6759e38b-8fbe-586f-a0a4-9ba985477d99
STIX ID: report--6759e38b-8fbe-586f-a0a4-9ba985477d99
Feed Name: Dark Reading
Researchers disclosed that Cursor AI's deeplink handling and a cramped confirmation dialog can be abused to hide MCP-server install instructions inside seemingly normal pull-request links; if clicked, this can install permission-rich malicious MCP servers that run arbitrary commands as the developer user, enabling code theft, secret exfiltration, or downstream compromise. Adversa AI recommended allowlisting, filtering install/execution paths, and agent-aware controls while Cursor investigates and tracks the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
