How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

The Cursor deeplink vulnerability that turns a “review this PR” click into remote code execution

calendar_today July 15, 2026 person Rony Utevsky domain adversa-ai

A crafted cursor:// link installs an attacker-controlled MCP server that executes unsandboxed commands under your account. The install dialog is supposed to be the safeguard, but it doesn’t reliably show the command being approved. The attack comes in two variants.

open_in_new Read original post