Proofpoint CursorJack Vulnerability Exposes Code Execution Risks in AI Development Environments
Article Content
- •CursorJack exploits MCP deeplinks in the Cursor IDE, allowing potential code execution.
- •User interaction is required for exploitation, increasing risk due to social engineering.
- •Proofpoint recommends security improvements to the MCP framework to mitigate risks.
Proofpoint Threat Research has identified a vulnerability named CursorJack that exploits deeplinks in the Cursor Integrated Development Environment (IDE). This method allows attackers to potentially execute arbitrary code or install malicious components by manipulating Model Context Protocol (MCP) deeplinks. The exploitation requires user interaction, specifically clicking on crafted links and approving installation prompts. The findings indicate that the deeplinks can be disguised as legitimate, posing risks to developers who often operate with elevated permissions. The research highlights the need for improved security measures in the MCP ecosystem, as the current reliance on user vigilance is insufficient. No automatic exploitation was observed, but the potential for abuse remains significant. Proofpoint has published a proof-of-concept code on GitHub and notified Cursor through its vulnerability-reporting channel, which classified the report as out-of-scope. The vulnerability is particularly concerning for environments that utilize AI tools, where users may be conditioned to accept prompts without thorough review.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Outlook and CVE-2025-54133 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…