0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

CursorJacking Vulnerability Remains Unpatched, Exposing Developer Credentials (layerxsecurity.com)

· 68d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Unpatched high-severity vulnerability
  • Exposes API keys and session tokens
  • Exploits extension permission loophole

"A critical vulnerability known as CursorJacking (CVSS 8.2) has been discovered in the Cursor AI code editor, allowing malicious extensions to steal API keys and session tokens from local credential storage. As of mid-May 2026, no patch has been released, leaving users vulnerable. The flaw exploits inadequate isolation of extension permissions, enabling unauthorized access to stored credentials. Developers using Cursor should revoke existing tokens and disable untrusted extensions until a fix is available. The vulnerability highlights ongoing security risks in AI-assisted coding tools."

Discussion Matrix

0 segments

no comments yet.