0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

CursorJacking: Cursor AI Editor API Key Theft via Extensions (layerxsecurity.com)

· 69d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • API keys stored in plaintext SQLite database.
  • Any extension can access due to lack of file system isolation.
  • Attackers can use stolen keys to access cloud services.
  • No patch from Cursor as of report.

"LayerX researchers disclosed 'CursorJacking,' a high-severity flaw where the Cursor AI editor stores sensitive API keys in an unencrypted local database accessible to any installed extension, risking full developer environment compromise."

Discussion Matrix

0 segments

no comments yet.