Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Use Rogue MCP Server to Inject Malicious Code to Control Over Cursor’s Built-in Browser

Hackers Use Rogue MCP Server to Inject Malicious Code to Control Over Cursor’s Built-in Browser

Posted on November 17, 2025November 17, 2025 By CWS

A important vulnerability permitting attackers to inject malicious code into Cursor’s embedded browser by means of compromised MCP (Mannequin Context Protocol) servers.

In contrast to VS Code, Cursor lacks integrity verification on its proprietary options, making it a first-rate goal for tampering.

The assault begins when a person downloads and registers a malicious MCP server by means of Cursor’s configuration file. As soon as enabled, the rogue server injects arbitrary JavaScript immediately into Cursor’s inside browser setting.

Attackers exploit the absence of checksum verification to switch unverified code throughout server registration.

How the Assault Works

The injection mechanism makes use of a easy however efficient method: “doc.physique.innerHTML ” is changed with attacker-controlled HTML, fully overwriting the web page and bypassing UI-level safety checks.

This enables attackers to show convincing faux login pages or malicious content material with out elevating suspicion.

Knostic researchers demonstrated this vulnerability by making a proof-of-concept that harvested person credentials by means of a faux login web page and transmitted them to a distant server.

The stolen credentials may grant attackers full entry to a developer’s workstation and company community. The assault requires minimal steps: customers should allow the MCP server and restart Cursor.

As soon as it runs, the malicious code stays energetic in each browser tab within the IDE, giving attackers ongoing entry to the system.

This vulnerability highlights a rising risk to the developer ecosystem. MCP servers require broad system permissions to perform, which means compromised servers can modify system elements, escalate privileges, and execute unauthorized actions with out person consciousness.

The risk extends past particular person builders, in response to the Knostic report. Organizations face important provide chain dangers as malicious MCP servers, IDE extensions, and prompts can execute code on developer machines, now the brand new safety perimeter.

Attackers can develop their attain from focused builders to whole company networks. The vulnerability underscores how AI coding instruments and brokers introduce increasing assault surfaces day by day.

In contrast to conventional growth instruments, these platforms combine a number of exterior elements with minimal visibility or management mechanisms.

Organizations ought to implement strict insurance policies round MCP server adoption, confirm server sources, and monitor IDE configurations. Knostic builders ought to train warning when downloading extensions and servers from untrusted sources.

The cursor was notified previous to publication, and the researchers withheld exploit code to forestall widespread abuse.

Comply with us on Google Information, LinkedIn, and X for day by day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:Browser, BuiltIn, Code, Control, Cursors, Hackers, Inject, Malicious, MCP, Rogue, Server

Post navigation

Previous Post: Network Communication Blocker Tool That Neutralizes EDR/AV
Next Post: Alice Blue Partners With AccuKnox For Regulatory Compliance

Related Posts

CISA Demands Removal of Outdated Network Devices CISA Demands Removal of Outdated Network Devices Cyber Security News
Hackers Exploit Networks for JavaScript Malware Hackers Exploit Networks for JavaScript Malware Cyber Security News
Critical Hikvision Vulnerability Threatens Wireless Access Points Critical Hikvision Vulnerability Threatens Wireless Access Points Cyber Security News
Microsoft January 2026 Security Update Causes Credential Prompt Failures in Remote Desktop Connections Microsoft January 2026 Security Update Causes Credential Prompt Failures in Remote Desktop Connections Cyber Security News
Critical SolarWinds Serv-U Vulnerabilities Let Attackers Execute Malicious Code Remotely as Admin Critical SolarWinds Serv-U Vulnerabilities Let Attackers Execute Malicious Code Remotely as Admin Cyber Security News
Great Firewall of China’s Sensitive Data of Over 500GB+ Leaked Online Great Firewall of China’s Sensitive Data of Over 500GB+ Leaked Online Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark