CursorJacking: Cursor AI Editor API Key Theft via Extensions (layerxsecurity.com)
0xBASE INTEL BRIEF
- API keys stored in plaintext SQLite database.
- Any extension can access due to lack of file system isolation.
- Attackers can use stolen keys to access cloud services.
- No patch from Cursor as of report.
"LayerX researchers disclosed 'CursorJacking,' a high-severity flaw where the Cursor AI editor stores sensitive API keys in an unencrypted local database accessible to any installed extension, risking full developer environment compromise."
no comments yet.