Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Use Rogue MCP Server to Inject Malicious Code to Control Over Cursor’s Built-in Browser

Hackers Use Rogue MCP Server to Inject Malicious Code to Control Over Cursor’s Built-in Browser

Posted on November 17, 2025November 17, 2025 By CWS

A important vulnerability permitting attackers to inject malicious code into Cursor’s embedded browser by means of compromised MCP (Mannequin Context Protocol) servers.

In contrast to VS Code, Cursor lacks integrity verification on its proprietary options, making it a first-rate goal for tampering.

The assault begins when a person downloads and registers a malicious MCP server by means of Cursor’s configuration file. As soon as enabled, the rogue server injects arbitrary JavaScript immediately into Cursor’s inside browser setting.

Attackers exploit the absence of checksum verification to switch unverified code throughout server registration.

How the Assault Works

The injection mechanism makes use of a easy however efficient method: “doc.physique.innerHTML ” is changed with attacker-controlled HTML, fully overwriting the web page and bypassing UI-level safety checks.

This enables attackers to show convincing faux login pages or malicious content material with out elevating suspicion.

Knostic researchers demonstrated this vulnerability by making a proof-of-concept that harvested person credentials by means of a faux login web page and transmitted them to a distant server.

The stolen credentials may grant attackers full entry to a developer’s workstation and company community. The assault requires minimal steps: customers should allow the MCP server and restart Cursor.

As soon as it runs, the malicious code stays energetic in each browser tab within the IDE, giving attackers ongoing entry to the system.

This vulnerability highlights a rising risk to the developer ecosystem. MCP servers require broad system permissions to perform, which means compromised servers can modify system elements, escalate privileges, and execute unauthorized actions with out person consciousness.

The risk extends past particular person builders, in response to the Knostic report. Organizations face important provide chain dangers as malicious MCP servers, IDE extensions, and prompts can execute code on developer machines, now the brand new safety perimeter.

Attackers can develop their attain from focused builders to whole company networks. The vulnerability underscores how AI coding instruments and brokers introduce increasing assault surfaces day by day.

In contrast to conventional growth instruments, these platforms combine a number of exterior elements with minimal visibility or management mechanisms.

Organizations ought to implement strict insurance policies round MCP server adoption, confirm server sources, and monitor IDE configurations. Knostic builders ought to train warning when downloading extensions and servers from untrusted sources.

The cursor was notified previous to publication, and the researchers withheld exploit code to forestall widespread abuse.

Comply with us on Google Information, LinkedIn, and X for day by day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:Browser, BuiltIn, Code, Control, Cursors, Hackers, Inject, Malicious, MCP, Rogue, Server

Post navigation

Previous Post: Network Communication Blocker Tool That Neutralizes EDR/AV
Next Post: Alice Blue Partners With AccuKnox For Regulatory Compliance

Related Posts

RondoDox Botnet’s Expansive Exploit Arsenal and IP Tactics RondoDox Botnet’s Expansive Exploit Arsenal and IP Tactics Cyber Security News
Researchers Detailed Techniques to Detect Outlook NotDoor Backdoor Malware Researchers Detailed Techniques to Detect Outlook NotDoor Backdoor Malware Cyber Security News
Red Bull-Themed Phishing Attacks Steal Job Seekers Login Credentials Red Bull-Themed Phishing Attacks Steal Job Seekers Login Credentials Cyber Security News
Chinese Hackers Exploit Routers for Hidden Cyber Attacks Chinese Hackers Exploit Routers for Hidden Cyber Attacks Cyber Security News
Critical Cisco Flaw Allows Remote Command Execution Critical Cisco Flaw Allows Remote Command Execution Cyber Security News
Charging Cable that Hacks your Device to Record Keystrokes and Control Wi-Fi Charging Cable that Hacks your Device to Record Keystrokes and Control Wi-Fi Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit GitHub Actions to Insert Miasma Malware
  • AI Safety Leadership in Flux as Director Resigns
  • Hackers Exploit Government Sites for Malware Distribution
  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit GitHub Actions to Insert Miasma Malware
  • AI Safety Leadership in Flux as Director Resigns
  • Hackers Exploit Government Sites for Malware Distribution
  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark