Opening SecureFlowData Exfiltration via an MCP Server used by Cursor
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

MITRE ATLAS mitre-atlas-cs0045

Data Exfiltration via an MCP Server used by Cursor

  • Autonomous Agents
  • Tool Integrations & MCP
  • Data Exfiltration
  • Credential & Identity Theft

The Backslash Security Research Team demonstrated that a Model Context Protocol (MCP) tool can be used as a vector for an indirect prompt injection attack on Cursor, potentially leading to the execution of malicious shell commands. The Backslash Security Research Team created a proof-of-concept MCP server capable of scraping webpages. When a user asks Cursor to use the tool to scrape a site containing a malicious prompt, the prompt is injected into Cursor's context. The prompt instructs Cursor to execute a shell command to exfiltrate the victim's AI agent configuration files containing credentials. Cursor does prompt the user before executing the malicious command, potentially mitigating the attack.

Mapped threat techniques

Source

Updated