A critical vulnerability allows attackers to inject malicious code into Cursor's built-in browser via compromised MCP (Model Context Protocol) servers. Unlike VS Code, Cursor lacks integrity verification in its proprietary functions, making it a prime target for compromise.
See also: CISO: New tools for MCP server security

The attack begins when a user downloads and registers a malicious MCP server via Cursor's configuration file. Once activated, the rogue server injects arbitrary JavaScript directly into the Cursor browser's internal environment. Attackers exploit the lack of checksum verification to modify unverified code during server registration.
The injection mechanism uses a simple but effective technique: “document.body.innerHTML” is replaced with attacker-controlled HTML, completely replacing the page and bypassing UI-level security checks. This allows attackers to display convincing fake login pages or malicious content without raising suspicion.
Knostic researchers demonstrated this vulnerability by creating a PoC that collected user credentials via a fake login page and transmitted them to a remote server. The stolen credentials could give attackers full access to a developer's workstation and corporate network. The attack requires minimal steps: users need to enable the MCP server and restart Cursor.
Once executed, the malicious code remains active in every browser tab in the IDE, giving attackers continuous access to the system.
See also: Prompt hijacking compromises MCP-based AI workflows

This vulnerability highlights a growing threat to the developer ecosystem. MCP servers require broad system privileges to operate, meaning compromised servers can modify system components, escalate privileges, and perform unauthorized actions without the user's knowledge.
The threat extends beyond individual developers, according to the Knostic report. Organizations face significant risks in the supply chain, as malicious MCP servers, IDE extensions, and prompts can execute code on developer machines, which now form the new security perimeter.
Attackers can extend their reach from targeted developers to entire corporate networks. The vulnerability highlights how coding tools and AI agents introduce ever-expanding attack surfaces. Unlike traditional development tools, these platforms integrate multiple external components with little visibility or control mechanisms.
Organizations should implement strict policies around MCP server adoption, verify server sources, and monitor IDE configurations. Developers should be cautious about downloading extensions and servers from untrusted sources.
See also: MCPTotal launches for secure enterprise workflow management MCP

Cursor was notified before publication, and researchers hid the exploit code to prevent widespread abuse.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
