logo

'CursorJack’ Attack Path Exposes Code Execution Risk in AI Development Environment

ID: 60228842-a619-5ab6-b780-17ce469af38b

STIX ID: report--60228842-a619-5ab6-b780-17ce469af38b

Feed Name: Infosecurity Magazine (News)

Threat Score
50/100

Date Published: 2026-03-17

Date Updated: 2026-04-22

...
...

Proofpoint researchers disclosed "CursorJack", a vulnerability in the Cursor IDE that abuses MCP deeplinks to embed malicious configuration and enable local code execution or installation of remote malicious components if a user clicks a crafted link and approves an installation prompt; exploitation requires user interaction, no zero-click exploit was observed, a PoC was published and Cursor was notified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.