ThreatCluster

Rogue MCP Servers Exploit Vulnerability in Cursor's Internal Browser

First seen 2 Dec 2025, 18:33 UTC CsoonlineCybersecuritynews 78% similarity 8

Article Content

Browse articles
ThreatCluster

Hackers are exploiting a critical vulnerability in Cursor, an AI-powered code editor, by using compromised Model Context Protocol (MCP) servers to inject malicious code. This attack allows the rogue servers to manipulate Cursor's internal browser, potentially replacing legitimate login pages with attacker-controlled ones. The lack of integrity verification in Cursor's proprietary features makes it particularly susceptible to these attacks.

ThreatCluster AI How this analysis works

Community

Browse all →