Skip to content

Hackers Use Rogue MCP Server to Inject Malicious Code and Control the Cursor's Built

Cybersecuritynews • November 17, 2025

A critical vulnerability allowing attackers to inject malicious code into Cursor’s embedded browser through compromised MCP (Model Context Protocol) servers.

Unlike VS Code , Cursor lacks integrity verification on its proprietary features, making it a prime target for tampering.

The attack begins when a user downloads and registers a malicious MCP server through Cursor’s configuration file. Once enabled, the rogue server injects arbitrary JavaScript directly into Cursor’s internal browser environment.

Attackers exploit the absence of checksum verification to modify unverified code during server registration.

The injection mechanism uses a simple but effective technique: “document.body.innerHTML ” is replaced with attacker-controlled HTML, completely overwriting the page and bypassing UI-level security checks.

This allows attackers to display convincing fake login pages or malicious content without raising suspicion.

Knostic researchers demonstrated this vulnerability by creating a proof-of-concept that harvested user credentials through a fake login page and transmitted them to a remote server.

The stolen credentials could grant attackers complete access to a developer’s workstation and corporate network. The attack requires minimal steps: users must enable the MCP server and restart Cursor.

Once it runs, the malicious code stays active in every browser tab in the IDE, giving attackers ongoing access to the system.

This vulnerability highlights a growing threat to the developer ecosystem. MCP servers require broad system permissions to function, meaning compromised servers can modify system components, escalate privileges, and execute unauthorized actions without user awareness.

The threat extends beyond individual developers, according to the Knostic report. Organizations face significant supply chain risks as malicious MCP servers, IDE extensions, and prompts can execute code on developer machines, now the new security perimeter.

Attackers can expand their reach from targeted developers to entire corporate networks. The vulnerability underscores how AI coding tools and agents introduce expanding attack surfaces daily.

Unlike traditional development tools, these platforms integrate multiple external components with minimal visibility or control mechanisms.

Organizations should implement strict policies around MCP server adoption, verify server sources, and monitor IDE configurations. Knostic developers should exercise caution when downloading extensions and servers from untrusted sources.

The cursor was notified prior to publication, and the researchers withheld exploit code to prevent widespread abuse.

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

A new open-source tool called SilentButDeadly has emerged, designed to disrupt Endpoint Detection and Response…

A serious security flaw in Cisco Catalyst Center Virtual Appliance has been discovered that allows…

A proof-of-concept (PoC) exploit tool for CVE-2025-64446 has been publicly released on GitHub. This vulnerability,…

A severe remote code execution (RCE) flaw has been uncovered in pgAdmin4, the popular open-source…

A new threat targeting Chinese users has appeared with a dangerous ability to shut down…

Attackers are using fake invoice emails to spread XWorm, a remote-access trojan that quietly steals…