A new proof-of-concept attack shows that malicious Model Context Protocol servers can inject JavaScript into Cursor’s browser — and potentially leverage the IDE’s privileges to perform system tasks.
The Model Context Protocol (mCP) is fundamentally changing how businesses operate by allowing AI agents to automate tasks across a wide range of tools and systems. By integrating platforms such as ...