For the longest time, I didn’t understand why Cursor had to be a dedicated app built on VS Code when it could have just been an extension. It didn’t seem to add much beyond an AI copilot layer on top ...
A new proof-of-concept attack shows that malicious Model Context Protocol servers can inject JavaScript into Cursor’s browser — and potentially leverage the IDE’s privileges to perform system tasks.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results