'CursorJack’ Attack Path Exposes Code Execution Risk in AI Development Environment
ID: 60228842-a619-5ab6-b780-17ce469af38b
STIX ID: report--60228842-a619-5ab6-b780-17ce469af38b
Feed Name: Infosecurity Magazine (News)
Threat Score
Proofpoint researchers disclosed "CursorJack", a vulnerability in the Cursor IDE that abuses MCP deeplinks to embed malicious configuration and enable local code execution or installation of remote malicious components if a user clicks a crafted link and approves an installation prompt; exploitation requires user interaction, no zero-click exploit was observed, a PoC was published and Cursor was notified.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
