Skip to content
CursorJack Vulnerability Exposes Code Execution Risks in AI Development Environments

CursorJack Vulnerability Exposes Code Execution Risks in AI Development Environments

First seen 17 Mar 2026, 15:08 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 18, 2026 at 14:43 UTC
  • CursorJack exploits MCP deeplinks in the Cursor IDE, allowing potential code execution.
  • User interaction is required for exploitation, increasing risk due to social engineering.
  • Proofpoint recommends security improvements to the MCP framework to mitigate risks.

Proofpoint Threat Research has identified a vulnerability named CursorJack that exploits deeplinks in the Cursor Integrated Development Environment (IDE). This method allows attackers to potentially execute arbitrary code or install malicious components by manipulating Model Context Protocol (MCP) deeplinks. The exploitation requires user interaction, specifically clicking on crafted links and approving installation prompts. The findings indicate that the deeplinks can be disguised as legitimate, posing risks to developers who often operate with elevated permissions. The research highlights the need for improved security measures in the MCP ecosystem, as the current reliance on user vigilance is insufficient. No automatic exploitation was observed, but the potential for abuse remains significant. Proofpoint has published a proof-of-concept code on GitHub and notified Cursor through its vulnerability-reporting channel, which classified the report as out-of-scope. The vulnerability is particularly concerning for environments that utilize AI tools, where users may be conditioned to accept prompts without thorough review.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 176d ago How this analysis works

Timeline

2025-08-01
CVE-2025-54133 published
2025-08-01
CVE-2025-54136 published
2026-01-15
First public PoC for CursorJack released
2026-03-17
Proofpoint publishes findings on CursorJack vulnerability
Date unknown
Cursor notified through vulnerability-reporting channel

More articles in this cluster (2)

Following this threat?

Track Outlook and CVE-2025-54133 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed