Hidden Prompt Injections Can Hijack AI Code Assistants
How Hidden Prompt Injections Can Hijack AI Code Assistants Like Cursor
Published on July 31, 2025
Reading Time: 5 Minutes
By Kasimir Schulz, Kenneth Yeung, Tom Bonner
Summary
AI tools like Cursor are changing how software gets written, making coding faster, easier, and smarter. But HiddenLayer’s latest research reveals a major risk: attackers can secretly trick these tools into performing harmful actions without you ever knowing.
In this blog, we show how something as innocent as a GitHub README file can be used to hijack Cursor’s AI assistant. With just a few hidden lines of text, an attacker can steal your API keys, your SSH credentials, or even run blocked system commands on your machine.
Our team discovered and reported several vulnerabilities in Cursor that, when combined, created a powerful attack chain that could exfiltrate sensitive data without the user’s knowledge or approval. We also demonstrate how HiddenLayer’s AI Detection and Response (AIDR) solution can stop these attacks in real time.
This research isn’t just about Cursor. It’s a warning for all AI-powered tools: if they can run code on your behalf, they can also be weaponized against you. As AI becomes more integrated into everyday software development, securing these systems becomes essential.
Introduction
Cursor is an AI-powered code editor designed to help developers write code faster and more intuitively by providing intelligent autocomplete, automated code suggestions, and real-time error detection. It leverages advanced machine learning models to analyze coding context and streamline software development tasks. As adoption of AI-assisted coding grows, tools like Cursor play an increasingly influential role in shaping how developers produce and manage their codebases.
Much like other LLM-powered systems capable of ingesting data from external sources, Cursor is vulnerable to a class of attacks known as Indirect Prompt Injection. Indirect Prompt Injections cause an LLM to disobey instructions set by the application’s developer and instead complete an attacker-defined task. Other organizations have demonstrated indirect attacks on Cursor via invisible characters in rule files, and we’ve shown this concept via emails and documents in Google’s Gemini for Workspace. In this blog, we will use indirect prompt injection combined with several vulnerabilities found and reported by our team to demonstrate what an end-to-end attack chain against an agentic system like Cursor may look like.
Putting It All Together
In Cursor’s Auto-Run mode, users can set denied commands that force Cursor to request user permission before running them. However, a security vulnerability reported by both HiddenLayer and BackSlash allows for prompts that can bypass the denylist. In the video below, we show how an attacker can exploit such a vulnerability by using targeted indirect prompt injections to exfiltrate data from a user’s system and execute arbitrary code.
Exfiltration of an OpenAI API key via curl in Cursor, despite curl being explicitly blocked on the Denylist
In the attack, an attacker set up a git repository with a prompt injection hidden within a comment block. When the victim viewed the project on GitHub and asked Cursor to clone the project, the prompt injection took over the AI model and forced it to use the grep tool to find any keys in the user's workspace before exfiltrating them with curl. This happened without the user’s permission being requested.
Taking It All Apart
The key components used for the attack can be reused without much knowledge to perform similar attacks against most agentic systems.
Key Components for Attack
- Malicious Instruction Control: The model must be influenced to execute unwanted tasks through various insertion methods into its context window.
- Tool Accessibility: Attackers identify which commands the system can execute that don’t prompt for user permission.
- Covert Instruction Delivery: Using comment blocks and other non-intrusive methods to insert malicious commands.
Using indirect prompt injections via a GitHub README.md file, we carried out a series of multi-step attacks designed to compromise systems while remaining undetected.
Example of Markdown Injection
# Setup Instructions
To use this template for your own project:
1. **Clone the Repository**
```bash
git clone https://github.com/<Attacker Org>/ai_project_template.git your_project_name
cd your_project_name
- Customize the Project
- Rename the repo and update references.
- Start editing the code inside the ./src/ directory.
- Run Your Project
- The entry point and structure is entirely up to you.