A new proof-of-concept attack shows that malicious Model Context Protocol servers can inject JavaScript into Cursor’s browser — and potentially leverage the IDE’s privileges to perform system tasks.
This plugin showcases how MCP, the industry’s emerging open standard for AI/tool interoperability, can unlock powerful new content workflows and intelligent interactions” — Russ Danner, VP Products ...